OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-69213: Http4s Ember HTTP/2 has an unbounded outbound frame queue

GitHub Advisories · officialPublished Sep 15, 2026Risk 37/100

Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because the connection emits a control frame in response to inbound frames it does not flow-control: one `PING` ACK per `PING`, one `SETTINGS` ACK per `SETTINGS`, and a `WINDOW_UPDATE` per inbound DATA. A single unauthenticated connection can therefore exhaust heap and OOM the process. This affects an ember server (malicious client) and an ember client (malicious/compromised server that floods the client and stops reading its ACKs). ## Impact Unauthenticated remote denial of service (OOM) against any ember server built `.withHttp2`, from a single connection, at negligible attacker cost (tiny control frames). Also affects an ember client talking to a hostile HTTP/2 server. ## Preconditions - Ember server or client built `.withHttp2`, speaking to a hostile or compromised peer. ## Workarounds - Disable HTTP/2 (do not call `.withHttp2`).

Upgrade affected packages to a patched version: org.http4s:http4s-ember-core_2.12 0.23.35, org.http4s:http4s-ember-core_2.13 0.23.35, org.http4s:http4s-ember-core_3 0.23.35, org.http4s:http4s-ember-core_3 1.0.0-M47, org.http4s:http4s-ember-core_2.13 1.0.0-M47.

Vendor
Not specified
Product
org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source