{"apiVersion":"1.0","identifier":"CVE-2026-73495","description":"blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names and values, including X-Forwarded-For and internal authorization headers, that a fronting proxy sanitized from the request-header section, bypassing header-based trust decisions in the application. Any http4s application using BlazeServerBuilder over HTTP/1.1 whose routes or middleware trust proxy-set headers, including X-Forwarded-For, X-Real-IP, and X-Forwarded-Host, is affected. If a fronting proxy strips or normalizes those headers but forwards chunked bodies with trailers intact, an attacker can spoof client IP for allow-lists, rate limits, or auditing, forge the https scheme, or inject internal authorization headers. A promoted Connection: close trailer is also honored, allowing attacker-controlled termination of pooled backend connections. This issue is fixed in versions 0.23.18 and 1.0.0-M42.","publishedAt":"2026-08-12T22:17:16","lastModifiedAt":"2026-08-13T13:19:18","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73495","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00289,"riskScore":0.76,"affectedProduct":"blaze-server","affectedVersions":"cannotmatch","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73495","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73495","en":"https://www.redsauce.net/en/cves/CVE-2026-73495","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73495","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73495","de":"https://www.redsauce.net/de/cves/CVE-2026-73495","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73495","el":"https://www.redsauce.net/el/cves/CVE-2026-73495"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73495"}}