{"id":"GHSA-7ppr-r889-mcf2","title":"blaze: Unbounded WebSocket message aggregation in http4s-blaze-server","summary":"blaze: Unbounded WebSocket message aggregation in http4s-blaze-server","severity":"high","cvss":7.5,"cwe":["CWE-770"],"vendor":"http4s","product":"org.http4s:http4s-blaze-server_2.13","ecosystem":"maven","affected":["org.http4s:http4s-blaze-server_2.13 < 0.23.18","org.http4s:http4s-blaze-server_2.13 >= 1.0.0-M1, < 1.0.0-M42","org.http4s:http4s-blaze-server_2.12 < 0.23.18","org.http4s:http4s-blaze-server_3 >= 1.0.0-M1, < 1.0.0-M42"],"patched":["org.http4s:http4s-blaze-server_2.13 0.23.18","org.http4s:http4s-blaze-server_2.13 1.0.0-M42","org.http4s:http4s-blaze-server_2.12 0.23.18","org.http4s:http4s-blaze-server_3 1.0.0-M42"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7ppr-r889-mcf2","references":[{"url":"https://github.com/http4s/blaze/security/advisories/GHSA-7ppr-r889-mcf2"},{"url":"https://github.com/http4s/blaze/commit/173e8ca820a0d12110bfe409c72e9b9c3d28d471"},{"url":"https://github.com/http4s/blaze/commit/2ae13a74d55209b6573d5228d1aa94f0361a75d0"},{"url":"https://github.com/http4s/blaze/commit/fadbe6d0f7f59045425688d313c8d4804973d12f"},{"url":"https://github.com/http4s/blaze/releases/tag/v0.23.18"},{"url":"https://github.com/http4s/blaze/releases/tag/v1.0.0-M42"},{"url":"https://github.com/advisories/GHSA-7ppr-r889-mcf2"}],"tags":["ghsa","maven"],"ingestedAt":"2026-07-24T22:40:26.682Z","slug":"GHSA-7ppr-r889-mcf2","body":"## Overview\n\n## Summary\n\n`http4s-blaze-server` aggregates the fragments of an incoming WebSocket\nmessage with no limit on total size or fragment count. A client that\ncompletes a WebSocket handshake can send an unterminated fragmented\nmessage and drive unbounded heap growth in the server JVM, resulting in\ndenial of service via `OutOfMemoryError`.\n\n## Impact\n\nAny http4s application serving WebSocket routes over\n`BlazeServerBuilder` is affected; no non-default configuration is required,\nand `maxWebSocketBufferSize` does not bound the aggregate (it bounds only\nindividual frames). A single connection sending continuation frames that\nnever set FIN forces the server to buffer every fragment until the heap is\nexhausted, terminating the JVM with `OutOfMemoryError` on the blaze\nselector thread. Small fragments amplify the cost through per-frame object\noverhead, so a modest volume of wire bytes is sufficient. Where the\nWebSocket endpoint is reachable without authentication the attacker is\nunauthenticated and remote; where the handshake requires a principal, any\nauthenticated client can still trigger it.\n\n## Workarounds\n\n- No blaze-server configuration bounds the aggregate; `maxWebSocketBufferSize`\n  is not a mitigation.\n- Terminate/limit WebSocket traffic at a fronting layer that enforces\n  message-size and fragment limits, or disable WebSocket routes.\n- Longer term: blaze is EOL upstream; plan migration to a maintained\n  backend (e.g. ember).\n\n## Affected packages\n\n- `org.http4s:http4s-blaze-server_2.13 < 0.23.18`\n- `org.http4s:http4s-blaze-server_2.13 >= 1.0.0-M1, < 1.0.0-M42`\n- `org.http4s:http4s-blaze-server_2.12 < 0.23.18`\n- `org.http4s:http4s-blaze-server_3 >= 1.0.0-M1, < 1.0.0-M42`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.http4s:http4s-blaze-server_2.13 0.23.18`\n- `org.http4s:http4s-blaze-server_2.13 1.0.0-M42`\n- `org.http4s:http4s-blaze-server_2.12 0.23.18`\n- `org.http4s:http4s-blaze-server_3 1.0.0-M42`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}