What is CVE-2026-73495?
CVE-2026-73495: A vulnerability in the Scala blaze library allows merging of HTTP/1.1 chunked-body trailer fields into Request.headers. A remote, unauthenticated attacker can exploit this to inject arbitrary headers. Users should upgrade to versions 0.23.18, 1.0.0-M42 or later to mitigate the issue.
Azərbaycanca: CVE-2026-73495: blaze Scala kitabxanasında aşkar edilən bu boşluq, HTTP/1.1 sorğularında chunked-body trailer başlıqlarının Request.headers-ə birləşdirilməsinə imkan verir. Uzaqdan təsdiqlənməmiş hücumçu bu yolla arzuolunmaz başlıq inyeksiyası həyata keçirə bilər. Təsirə məruz qalan sistemlərdə 0.23.18 və 1.0.0-M42 öncəsi versiyalar yenilənməlidir.
FAQ2
Which blaze versions are affected by CVE-2026-73495?
All versions prior to 0.23.18 and 1.0.0-M42 are affected.
What kind of attack can be performed by exploiting CVE-2026-73495?
A header injection attack can be performed by a remote unauthenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.