Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
GHSA-9vwc-pc8p-253q · CVE-2026-69203
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGS_MAX_CONCURRENT_STREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.
Impact
Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).
The same unchecked allocation path is reachable on the client via server-initiated PUSH_PROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.
Preconditions
- Server: with
.withHttp2enabled. - Client: makes HTTP/2 requests to malicious or compromised sites.
enablePushis not enforced.
Workarounds
- Disable HTTP/2 on
EmberServerBuilderorEmberClientBuilder(default) - Client only: avoid HTTP/2 to untrusted servers until patched.
References
- WEB https://github.com/http4s/http4s/security/advisories/GHSA-9vwc-pc8p-253q
- WEB https://github.com/http4s/http4s/commit/4983de1f93f2caaa3b9de310cf6a9db32c50d66e
- PACKAGE https://github.com/http4s/http4s
- WEB https://github.com/http4s/http4s/releases/tag/v0.23.35
- WEB https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
Ready to move
Start Securing
Free, no credit card | First findings in minutes