Http4s Ember HTTP/2: unbounded inbound body buffering
GHSA-6m4x-pp6q-5jmm · CVE-2026-69202
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes
received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore
provides no backpressure: a peer can stream a large or unbounded body faster than the application drains it and the connection retains every payload in heap.
This is the read-path mirror of the outbound queue issue.
This affects an Ember receiving a request body and an Ember client receiving a response body from a hostile server.
Impact
Unauthenticated remote denial of service (OOM) against any Ember server built.withHttp2 for a non-draining or slow-draining route, and against an Ember client consuming from a hostile or compromised server.
Workarounds
- Disable HTTP/2 to remove the vector entirely.
- Apply an aggregate request-entity size limit (e.g.
EntityLimitermiddleware) on routes that consume the body. - Ensure handlers fully drain request bodies with aggressive idle timeouts.
References
- WEB https://github.com/http4s/http4s/security/advisories/GHSA-6m4x-pp6q-5jmm
- WEB https://github.com/http4s/http4s/commit/22d2335975d02dc9fb9fb75cfe002279521d86ac
- PACKAGE https://github.com/http4s/http4s
- WEB https://github.com/http4s/http4s/releases/tag/v0.23.35
- WEB https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
Ready to move
Start Securing
Free, no credit card | First findings in minutes