{"id":"CVE-2026-73493","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73493","summary":"blaze: Unbounded WebSocket message aggregation in http4s-blaze-server","details":"## Summary\n\n`http4s-blaze-server` aggregates the fragments of an incoming WebSocket\nmessage with no limit on total size or fragment count. A client that\ncompletes a WebSocket handshake can send an unterminated fragmented\nmessage and drive unbounded heap growth in the server JVM, resulting in\ndenial of service via `OutOfMemoryError`.\n\n## Impact\n\nAny http4s application serving WebSocket routes over\n`BlazeServerBuilder` is affected; no non-default configuration is required,\nand `maxWebSocketBufferSize` does not bound the aggregate (it bounds only\nindividual frames). A single connection sending continuation frames that\nnever set FIN forces the server to buffer every fragment until the heap is\nexhausted, terminating the JVM with `OutOfMemoryError` on the blaze\nselector thread. Small fragments amplify the cost through per-frame object\noverhead, so a modest volume of wire bytes is sufficient. Where the\nWebSocket endpoint is reachable without authentication the attacker is\nunauthenticated and remote; where the handshake requires a principal, any\nauthenticated client can still trigger it.\n\n## Workarounds\n\n- No blaze-server configuration bounds the aggregate; `maxWebSocketBufferSize`\n  is not a mitigation.\n- Terminate/limit WebSocket traffic at a fronting layer that enforces\n  message-size and fragment limits, or disable WebSocket routes.\n- Longer term: blaze is EOL upstream; plan migration to a maintained\n  backend (e.g. ember).","published":"2026-07-24T22:28:05Z","modified":"2026-08-12T21:15:08.595564713Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.http4s:http4s-blaze-server_2.13","fixedVersion":"0.23.18"},{"ecosystem":"Maven","name":"org.http4s:http4s-blaze-server_2.13","fixedVersion":"1.0.0-M42"},{"ecosystem":"Maven","name":"org.http4s:http4s-blaze-server_2.12","fixedVersion":"0.23.18"},{"ecosystem":"Maven","name":"org.http4s:http4s-blaze-server_3","fixedVersion":"1.0.0-M42"}],"fix":{"url":"https://github.com/http4s/blaze/commit/173e8ca820a0d12110bfe409c72e9b9c3d28d471","label":"http4s/blaze@173e8ca"},"references":[{"type":"WEB","url":"https://github.com/http4s/blaze/security/advisories/GHSA-7ppr-r889-mcf2"},{"type":"WEB","url":"https://github.com/http4s/blaze/commit/173e8ca820a0d12110bfe409c72e9b9c3d28d471"},{"type":"WEB","url":"https://github.com/http4s/blaze/commit/2ae13a74d55209b6573d5228d1aa94f0361a75d0"},{"type":"WEB","url":"https://github.com/http4s/blaze/commit/fadbe6d0f7f59045425688d313c8d4804973d12f"},{"type":"PACKAGE","url":"https://github.com/http4s/blaze"},{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v0.23.18"},{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v1.0.0-M42"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T21:15:08.595564713Z"}}