SCA: security update for org.http4s:http4s-blaze-server_2.12, org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_3 (GHSA-7ppr-r889-mcf2)

high Tenable Cloud Security Plugin ID 445902

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18
and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on
total size or fragment count. A client that completes a WebSocket handshake can send an unterminated
fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service
through OutOfMemoryError. Any http4s application serving WebSocket routes over BlazeServerBuilder is
affected, no non-default configuration is required, and maxWebSocketBufferSize does not bound the
aggregate because it bounds only individual frames. A single connection sending continuation frames that
never set FIN forces the server to buffer every fragment until the heap is exhausted, terminating the JVM
with OutOfMemoryError on the blaze selector thread. Small fragments amplify the cost through per-frame
object overhead, so a modest volume of wire bytes is sufficient. This issue is fixed in versions 0.23.18
and 1.0.0-M42. (CVE-2026-73493)

Solution

Update the org.http4s:http4s-blaze-server_2.12 library and its related packages to version 0.23.18 or later.

See Also

https://github.com/advisories/GHSA-7ppr-r889-mcf2

Plugin Details

Severity: High

ID: 445902

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/13/2026

Updated: 8/13/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-73493

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/24/2026

Vulnerability Publication Date: 7/24/2026

Reference Information

CVE: CVE-2026-73493

cwe: CWE-770