HTTP Request Smuggling Affecting org.http4s:http4s-blaze-server_3 package, versions [,0.23.18)[1.0.0-M22,1.0.0-M42)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGHTTP4S-18313127
  • published26 Jul 2026
  • disclosed24 Jul 2026
  • creditERobertGII

Introduced: 24 Jul 2026

New CVE NOT AVAILABLE CWE-444  (opens in a new tab)

How to fix?

Upgrade org.http4s:http4s-blaze-server_3 to version 0.23.18, 1.0.0-M42 or higher.

Overview

Affected versions of this package are vulnerable to HTTP Request Smuggling in the process that merges HTTP/1.1 chunked-body trailer fields into Request.headers. An attacker can inject arbitrary HTTP headers by sending specially crafted trailer fields, potentially bypassing header-based trust decisions such as client IP allow-lists, rate-limits, audit logging, or internal authentication enforced by upstream proxies. This may allow spoofing of client identity or unauthorized access to protected resources.

Workaround

This vulnerability can be mitigated by deploying behind a proxy that removes trailer fields or rejects requests using trailers before forwarding, and by avoiding trust decisions based on headers that rely on proxy sanitization.

CVSS Base Scores

version 4.0
version 3.1