GHSA-9vwc-pc8p-253qHighCVSS 7.5

Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGS_MAX_CONCURRENT_STREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.

Impact

Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).

The same unchecked allocation path is reachable on the client via server-initiated PUSH_PROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.

Preconditions

  • Server: with .withHttp2 enabled.
  • Client: makes HTTP/2 requests to malicious or compromised sites. enablePush is not enforced.

Workarounds

  • Disable HTTP/2 on EmberServerBuilder or EmberClientBuilder (default)
  • Client only: avoid HTTP/2 to untrusted servers until patched.

🎯 Affected products5

  • maven/org.http4s:http4s-ember-core_2.12:<= 0.23.34
  • maven/org.http4s:http4s-ember-core_2.13:<= 0.23.34
  • maven/org.http4s:http4s-ember-core_3:<= 0.23.34
  • maven/org.http4s:http4s-ember-core_2.13:>= 1.0.0-M1, <= 1.0.0-M46
  • maven/org.http4s:http4s-ember-core_3:>= 1.0.0-M1, <= 1.0.0-M46

🔗 References (5)