Http4s Ember HTTP/2 has an unbounded outbound frame queue
GHSA-8f3q-3jmv-7prw · CVE-2026-69213
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (writeLoop). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because the connection emits a control frame in response to inbound frames it does not flow-control: one PING ACK per PING, one SETTINGS ACK per SETTINGS, and a WINDOW_UPDATE per inbound DATA. A single unauthenticated connection can therefore exhaust heap and OOM the process.
This affects an ember server (malicious client) and an ember client (malicious/compromised server that floods the client and stops reading its ACKs).
Impact
Unauthenticated remote denial of service (OOM) against any ember server built .withHttp2, from a single connection, at negligible attacker cost (tiny control frames). Also affects an ember client talking to a hostile HTTP/2 server.
Preconditions
- Ember server or client built
.withHttp2, speaking to a hostile or compromised peer.
Workarounds
- Disable HTTP/2 (do not call
.withHttp2).
References
- WEB https://github.com/http4s/http4s/security/advisories/GHSA-8f3q-3jmv-7prw
- WEB https://github.com/http4s/http4s/commit/13fe24d6440bde2f1eb70121486cf59c278e6bae
- PACKAGE https://github.com/http4s/http4s
- WEB https://github.com/http4s/http4s/releases/tag/v0.23.35
- WEB https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
Ready to move
Start Securing
Free, no credit card | First findings in minutes