HIGH
http4s
CVE published 2026-08-12
CVE-2026-73495
CVE-2026-73495 debrief: The Blaze library, used for building asynchronous pipelines, has a vulnerability that allows unauthenticated remote clients to inject arbitrary headers into http4s applications using BlazeServerBuilder over HTTP/1.1. This can lead to bypassing header-based trust decisions, spoofing client IP for allow-lists, rate limits, or auditing, forging the https scheme, or injecting internal [truncated]