org.http4s:blaze-http_3 vulnerabilities
CVEs whose affected-version data names the org.http4s:blaze-http_3 package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-mhvj-jhpq-885vHigh· 7.4blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-46q4-43ph-c6frHigh· 7.4blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
▾ Twilighthttp4s · org.http4s:blaze-http_2.13via GHSA