HIGH 7.5 Maven

Http4s Ember HTTP/2: unbounded inbound body buffering

GHSA-6m4x-pp6q-5jmm · CVE-2026-69202

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes
received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore
provides no backpressure: a peer can stream a large or unbounded body faster than the application drains it and the connection retains every payload in heap.

This is the read-path mirror of the outbound queue issue.

This affects an Ember receiving a request body and an Ember client receiving a response body from a hostile server.

Impact

Unauthenticated remote denial of service (OOM) against any Ember server built
.withHttp2 for a non-draining or slow-draining route, and against an Ember client consuming from a hostile or compromised server.

Workarounds

  • Disable HTTP/2 to remove the vector entirely.
  • Apply an aggregate request-entity size limit (e.g. EntityLimiter middleware) on routes that consume the body.
  • Ensure handlers fully drain request bodies with aggressive idle timeouts.

Ready to move

Start Securing

Free, no credit card | First findings in minutes