OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-69203: Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

GitHub Advisories · officialPublished Sep 15, 2026Risk 37/100

An ember server with HTTP/2 enabled (`.withHttp2`) does not enforce `SETTINGS_MAX_CONCURRENT_STREAMS` on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap. ## Impact Unauthenticated remote denial of service (memory exhaustion) against any Ember server built `.withHttp2`. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487). The same unchecked allocation path is reachable on the client via server-initiated `PUSH_PROMISE` frames, so a malicious or compromised server can exhaust an ember-client's heap the same way. ## Preconditions - Server: with `.withHttp2` enabled. - Client: makes HTTP/2 requests to malicious or compromised sites. `enablePush` is not enforced. ## Workarounds - Disable HTTP/2 on `EmberServerBuilder` or `EmberClientBuilder` (default) - Client only: avoid HTTP/2 to untrusted servers until patched.

Upgrade affected packages to a patched version: org.http4s:http4s-ember-core_2.12 0.23.35, org.http4s:http4s-ember-core_2.13 0.23.35, org.http4s:http4s-ember-core_3 0.23.35, org.http4s:http4s-ember-core_2.13 1.0.0-M47, org.http4s:http4s-ember-core_3 1.0.0-M47.

Vendor
Not specified
Product
org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source