CVE-2026-69203
Received Received - Intake

HTTP/2 Stream Flood in Http4s

Vulnerability report for CVE-2026-69203, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connection can open an unbounded number of streams, each retaining per-stream state until heap exhaustion. The same unchecked allocation is reachable in an ember-client through server-initiated PUSH_PROMISE frames because enablePush is not enforced. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s to 1.0.0-M47 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the http4s library's HTTP/2 server and client implementations. It allows unauthenticated attackers to open an unlimited number of concurrent HTTP/2 streams without enforcing the SETTINGS_MAX_CONCURRENT_STREAMS limit. Each stream retains server state in memory until heap exhaustion occurs, causing a denial of service.

Detection Guidance

To detect this vulnerability, monitor for excessive HTTP/2 streams or memory exhaustion on systems running vulnerable http4s versions. Check server logs for refused streams or connection resets. Use network tools like tcpdump or Wireshark to inspect HTTP/2 frames for abnormal stream creation rates.

Impact Analysis

An attacker could exploit this to crash your HTTP/2 server or client by consuming all available memory through excessive stream creation. This leads to service unavailability and potential downtime for applications relying on http4s.

Compliance Impact

This vulnerability primarily impacts system availability by enabling denial-of-service attacks through memory exhaustion. While it does not directly violate GDPR or HIPAA data protection requirements, it could lead to service disruptions that indirectly affect compliance by preventing timely access to personal data or protected health information.

Mitigation Strategies
  • Upgrade http4s to versions 0.23.35 or 1.0.0-M47 or later to enforce SETTINGS_MAX_CONCURRENT_STREAMS.
  • Disable HTTP/2 on EmberServerBuilder or EmberClientBuilder if upgrading is not immediately possible.
  • Avoid HTTP/2 with untrusted servers until patched versions are deployed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69203. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart