HIGH 7.5 Maven

Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

GHSA-9vwc-pc8p-253q · CVE-2026-69203

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGS_MAX_CONCURRENT_STREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.

Impact

Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).

The same unchecked allocation path is reachable on the client via server-initiated PUSH_PROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.

Preconditions

  • Server: with .withHttp2 enabled.
  • Client: makes HTTP/2 requests to malicious or compromised sites. enablePush is not enforced.

Workarounds

  • Disable HTTP/2 on EmberServerBuilder or EmberClientBuilder (default)
  • Client only: avoid HTTP/2 to untrusted servers until patched.

Ready to move

Start Securing

Free, no credit card | First findings in minutes