SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73494

HIGH · CVSS 7.4 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Blaze library for Java, specifically versions prior to 0.23.18 and from 1.0.0-M1 to 1.0.0-M42, is vulnerable due to lax HTTP/1.1 parsing that allows invalid header field names and other malformed requests. This can lead to serious security issues, including front-end authorization bypass and cache poisoning, especially when interacting with lenient proxies that interpret requests differently. Organizations using affected versions should prioritize updating to the fixed releases to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73494
Severity
HIGH
CVSS
7.4
EPSS
0.37%
Java

Original NVD Description

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.