What is CVE-2026-73493?
CVE-2026-73493 is a vulnerability in the http4s-blaze-server library where WebSocket message aggregation lacks limits on total size or fragment count. An attacker completing a WebSocket handshake can exhaust server resources by sending unlimited data. Versions prior to 0.23.18 and 1.0.0-M42 are affected, requiring immediate update.
Azərbaycanca: CVE-2026-73493, Http4s http4s-blaze-server kitabxanasında WebSocket mesajlarının ümumi ölçüsünə və ya fraqment sayına məhdudiyyət qoyulmaması səbəbindən yaranan zəiflikdir. Bu boşluqdan istifadə edən hücumçu, WebSocket handshake-ni tamamlayaraq server resurslarını tükədə bilər. 0.23.18 və 1.0.0-M42 versiyalarından əvvəlki versiyalar təsirlənir, dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which library was the CVE-2026-73493 vulnerability discovered?
This vulnerability was discovered in the http4s-blaze-server library.
Which versions are considered vulnerable for CVE-2026-73493?
Versions prior to 0.23.18 and 1.0.0-M42 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.