PatchSiren

http4s CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH http4s CVE published 2026-08-12

CVE-2026-73495

CVE-2026-73495 debrief: The Blaze library, used for building asynchronous pipelines, has a vulnerability that allows unauthenticated remote clients to inject arbitrary headers into http4s applications using BlazeServerBuilder over HTTP/1.1. This can lead to bypassing header-based trust decisions, spoofing client IP for allow-lists, rate limits, or auditing, forging the https scheme, or injecting internal [truncated]