CVE-2026-69209
Received Received - Intake

Memory Exhaustion in Http4s WebSocket Decoder

Vulnerability report for CVE-2026-69209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket handshake against an http4s-blaze-server or http4s-ember-server endpoint can exhaust server memory with oversized frames or fragmented messages. The patched decoder applies a configurable 64 MiB default limit to individual frames and defragmented messages through EmberServerBuilder.withMaxWebSocketMessageSize. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s to 1.0.0-M47 (exc)
http4s http4s 0.23.35
http4s http4s 1.0.0-M47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-69209 is a vulnerability in the Http4s library's WebSocket implementation. It allows a remote attacker to exhaust server memory by sending oversized or fragmented WebSocket messages. The issue occurs because the WebSocket decoder does not enforce limits on message size during defragmentation or frame processing, allowing clients to send messages up to Int.MaxValue in length.

Detection Guidance

Detecting this vulnerability requires monitoring for abnormal memory usage or WebSocket traffic patterns on servers running affected http4s versions. Check for processes consuming excessive memory during WebSocket connections. Use tools like netstat or ss to inspect active WebSocket connections and their payload sizes. Monitor server logs for errors related to WebSocket frame processing or memory exhaustion.

Impact Analysis

This vulnerability can lead to a denial of service (DoS) attack where an attacker remotely crashes or severely degrades the performance of a server by consuming all available memory. Servers exposing WebSocket endpoints are particularly at risk. The impact is limited to availability, as confidentiality and integrity are not affected.

Compliance Impact

This vulnerability primarily impacts system availability by enabling remote denial-of-service attacks through memory exhaustion. While it does not directly compromise data confidentiality or integrity, prolonged service disruption could indirectly affect compliance with standards like GDPR or HIPAA that require timely access to personal or health data. However, the CVE data does not provide specific details on compliance impacts.

Mitigation Strategies
  • Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later to apply the 64 MiB WebSocket message size limit.
  • Configure EmberServerBuilder.withMaxWebSocketMessageSize to enforce stricter limits if needed.
  • Restrict public exposure of WebSocket endpoints if not required for operations.
  • Monitor network traffic for unusually large WebSocket frames or fragmented messages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart