VYPR

blaze

by Blaze

CVEs (1)

  • CVE-2026-73494higJul 24, 2026
    risk 0.38cvss epss

    ### Summary Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/`) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default `BlazeServerBuilder` with no…