HTTP Request Smuggling Affecting org.http4s:blaze-http_2.13 package, versions [,0.23.18)[1.0.0-M33,1.0.0-M42)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGHTTP4S-18313143
  • published26 Jul 2026
  • disclosed24 Jul 2026
  • creditERobertGII

Introduced: 24 Jul 2026

New CVE NOT AVAILABLE CWE-444  (opens in a new tab)

How to fix?

Upgrade org.http4s:blaze-http_2.13 to version 0.23.18, 1.0.0-M42 or higher.

Overview

Affected versions of this package are vulnerable to HTTP Request Smuggling via the Java HTTP parser process. An attacker can bypass access controls, poison backend response queues, or manipulate cache contents by sending specially crafted HTTP/1.1 requests that exploit discrepancies in request boundary parsing between the server and an intermediary. This is only exploitable if a fronting proxy or intermediary interprets HTTP request boundaries differently than the backend parser.

Workaround

This vulnerability can be mitigated by deploying behind an RFC-strict reverse proxy (such as nginx, HAProxy, Envoy, or ALB) that rejects or re-serializes malformed requests at the edge.

CVSS Base Scores

version 4.0
version 3.1