A vulnerability was found in http4s blaze up to 0.23.17/1.0.0-M41 . It has been declared as critical . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper authorization. This vulnerability is registered as CVE-2026-73495 . It is possible to launch the attack remotely. No exploit is available. It is recommended to upgrade the affected component.