Answer in brief
CVE-2026-73493 records a High severity (CVSS 7.5) vulnerability in http4s-blaze-server: Unbounded WebSocket message aggregation. The current sources do not mark it as known exploited. The current feed maps http4s/blaze (generic), org.http4s:http4s-blaze-server_2.12 (maven), org.http4s:http4s-blaze-server_2.12 (maven), org.http4s:http4s-blaze-server_2.13 (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps http4s/blaze (generic), org.http4s:http4s-blaze-server_2.12 (maven), org.http4s:http4s-blaze-server_2.12 (maven), org.http4s:http4s-blaze-server_2.13 (maven) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| http4s/blazegeneric | < 0.23.18 || >= 1.0.0-M1, < 1.0.0-M42 | Not reported |
| org.http4s:http4s-blaze-server_2.12maven | >=0 <0.23.18 | 0.23.18 |
| org.http4s:http4s-blaze-server_2.12maven | <0.23.18 | 0.23.18 |
| org.http4s:http4s-blaze-server_2.13maven | >=0 <0.23.18 | 0.23.18 |
| org.http4s:http4s-blaze-server_2.13maven | >=1.0.0-M1 <1.0.0-M42 | 1.0.0-M42 |
| org.http4s:http4s-blaze-server_2.13maven | <0.23.18 | 0.23.18 |
| org.http4s:http4s-blaze-server_2.13maven | >=1.0.0-M1,<1.0.0-M42 | 1.0.0-M42 |
| org.http4s:http4s-blaze-server_3maven | >=1.0.0-M1 <1.0.0-M42 | 1.0.0-M42 |
| org.http4s:http4s-blaze-server_3maven | >=1.0.0-M1,<1.0.0-M42 | 1.0.0-M42 |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 8, 2026
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service through OutOfMemoryError. Any http4s application serving WebSocket routes over BlazeServerBuilder is affected, no non-default configuration is required, and maxWebSocketBufferSize does not bound the aggregate because it bounds only individual frames. A single connection sending continuation frames that never set FIN forces the server to buffer every fragment until the heap is exhausted, terminating the JVM with OutOfMemoryError on the blaze selector thread. Small fragments amplify the cost through per-frame object overhead, so a modest volume of wire bytes is sufficient. This issue is fixed in versions 0.23.18 and 1.0.0-M42.
Quoted source text, attributed separately from HOL analysis.