CVE-2026-69202
Received Received - Intake

Heap Exhaustion in Http4s via HTTP/2 Flow-Control

Vulnerability report for CVE-2026-69202, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the application, while each stream stores DATA in an unbounded channel. A hostile peer can therefore send a body faster than a slow or non-draining application consumes it, retaining payloads in heap on an ember-server or ember-client configured with withHttp2. The patch bounds the per-stream H2Connection body channel so application consumption applies backpressure. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ember ember_server to 0.23.35 (exc)
ember ember_client to 0.23.35 (exc)
ember ember_server to 1.0.0-M47 (exc)
ember ember_client to 1.0.0-M47 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Ember HTTP/2 stack in the http4s library. The HTTP/2 flow-control window is replenished based on bytes received from the network rather than bytes consumed by the application. This allows a malicious peer to send large or unbounded request or response bodies, causing the server or client to retain all payloads in memory indefinitely. The result is an unauthenticated remote denial-of-service (OOM) attack.

Detection Guidance

Monitor for unusual memory consumption patterns in applications using http4s-ember-core with HTTP/2 enabled. Check for processes with growing heap usage or frequent garbage collection pauses. Use tools like jcmd, jstat, or system monitoring to track memory allocation rates.

Impact Analysis

This vulnerability can lead to an out-of-memory (OOM) condition on affected systems. Servers using Ember with HTTP/2 may crash due to excessive memory consumption. Clients consuming responses from hostile servers may also experience crashes or degraded performance. The impact is high availability risk for services using vulnerable versions.

Compliance Impact

This vulnerability primarily impacts availability and resource management. While not directly a data breach, it could lead to service disruptions that may violate compliance requirements for uptime and reliability in GDPR, HIPAA, or other standards. Unplanned outages could result in non-compliance penalties depending on specific regulatory contexts.

Mitigation Strategies
  • Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later to apply the patch.
  • Disable HTTP/2 support in http4s if not required, falling back to HTTP/1.1.
  • Implement request-entity size limits to cap payload sizes.
  • Ensure request handlers fully drain body data with strict timeouts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69202. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart