Skip to content
archivevulnerability · 15 Sep 2026 · 20:01 UTC

GHSA-cp4q-fqw9-4hf6: Http4s Ember HTTP/2: unbounded continuation frame accumulation

VULNCVE-2026-69218source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for subsequent `CONTINUATION` frames. These accumulate unbounded until the connection closes. ### Impact A remote, unauthenticated peer can exhaust the heap on any Ember endpoint that has HTTP/2 enabled: - **ember-server with `.withHttp2`**: any HTTP/2 client can trigger this against any reachable path (including paths that return 404). No authentication is required because the attack completes before the request is decoded. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected