org.http4s:http4s-blaze-server_2.13 vulnerabilities
CVEs whose affected-version data names the org.http4s:http4s-blaze-server_2.13 package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-mhvj-jhpq-885vHigh· 7.4blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-7ppr-r889-mcf2High· 7.5blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA