CVE-2026-73494 | http4s blaze up to 0.23.17/1.0.0-M1-1.0.0-M41 HTTP/1.1 Parser parser BodyAndHeaderParser/Http1ServerParser authorization

SecurityVulns

A vulnerability was found in http4s blaze up to 0.23.17/1.0.0-M1-1.0.0-M41. It has been classified as critical. This affects the function BodyAndHeaderParser/Http1ServerParser of the file http/src/main/java/org/http4s/blaze/http/parser of the component HTTP1.1 Parser. Performing a manipulation results in authorization bypass.

This vulnerability was named CVE-2026-73494. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More