OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-69218: Http4s Ember HTTP/2: unbounded continuation frame accumulation

GitHub Advisories · officialPublished Sep 15, 2026Risk 37/100

When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for subsequent `CONTINUATION` frames. These accumulate unbounded until the connection closes. ### Impact A remote, unauthenticated peer can exhaust the heap on any Ember endpoint that has HTTP/2 enabled: - **ember-server with `.withHttp2`**: any HTTP/2 client can trigger this against any reachable path (including paths that return 404). No authentication is required because the attack completes before the request is decoded. - **ember-client with `.withHttp2`**: a malicious or compromised origin server can trigger this via the response header block. A single in-flight request is sufficient. Memory consumption is bounded only by the attacker's upload bandwidth and the connection lifetime. ### Prerequisites - `EmberServerBuilder` configured with `.withHttp2`. - For the server: the attacker can establish an HTTP/2 connection - For the client: the application makes a request to an attacker-controlled origin. HTTP/2 incoming headers exceeding the configured size limit are buffer in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. ### Patches The fix bounds the accumulated header-block size at `SETTINGS_MAX_HEADER_LIST_SIZE` (derived from `EmberServerBuilder.maxHeaderSize` / `EmberClientBuilder.maxResponseHeaderSize`). When a `CONTINUATION` frame would push the accumulated block over that limit, the connection is terminated with `GOAWAY`. The `receiveHeadersTimeout` additionally bounds how long an incomplete header block may remain open. ### Workarounds - Disable HTTP/2 (`.withHttp2`) until upgraded (default). It is off by default. - If HTTP/2 must remain enabled, place ember behind a reverse proxy that terminates HTTP/2 and speaks HTTP/1.1 to ember.

Upgrade affected packages to a patched version: org.http4s:http4s-ember-core_2.12 0.23.35, org.http4s:http4s-ember-core_2.13 0.23.35, org.http4s:http4s-ember-core_3 0.23.35, org.http4s:http4s-ember-core_2.13 1.0.0-M47, org.http4s:http4s-ember-core_3 1.0.0-M47.

Vendor
Not specified
Product
org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source