HIGHMaven →
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
Affected packages
- org.http4s:http4s-blaze-server_2.12— before 0.23.18
- org.http4s:http4s-blaze-server_2.13— before 0.23.18
- org.http4s:http4s-blaze-server_3— 1.0.0-M1 → 1.0.0-M42
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/http4s/blaze/security/advisories/GHSA-7ppr-r889-mcf2
- https://github.com/http4s/blaze/commit/173e8ca820a0d12110bfe409c72e9b9c3d28d471
- https://github.com/http4s/blaze/commit/2ae13a74d55209b6573d5228d1aa94f0361a75d0
- https://github.com/http4s/blaze/commit/fadbe6d0f7f59045425688d313c8d4804973d12f
- https://github.com/http4s/blaze
- https://github.com/http4s/blaze/releases/tag/v0.23.18
- https://github.com/http4s/blaze/releases/tag/v1.0.0-M42
Structured record: https://osv.dev/vulnerability/GHSA-7ppr-r889-mcf2
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta