CVE-2026-69210
Received Received - Intake

Denial of Service in Http4s WebSocket Implementation

Vulnerability report for CVE-2026-69210, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop then runs indefinitely, pins a worker at full CPU, and grows an ArrayBuffer without bound, resulting in denial of service. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s From 1.0.0-M1 (inc) to 1.0.0-M47 (exc)
http4s http4s to 1.0.0-M47 (exc)
http4s http4s 0.23.35
http4s http4s 1.0.0-M47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Http4s library, a Scala interface for HTTP services. It involves a flaw in the WebSocket FrameTranscoder where negative 64-bit payload lengths are incorrectly accepted. This causes the decoder to return empty frames without advancing the input buffer, leading to an infinite loop that consumes full CPU and memory, resulting in a denial of service.

Detection Guidance

This vulnerability can be detected by monitoring for abnormal CPU usage or memory growth on systems running vulnerable versions of http4s. Check for WebSocket endpoints exposed via Ember servers and inspect WebSocket frame lengths for negative values. Use network monitoring tools to detect infinite decode loops or excessive frame processing.

Impact Analysis

An attacker can exploit this by sending a malicious WebSocket frame to a vulnerable server. This causes the server's CPU to max out and memory to grow indefinitely, crashing or severely degrading the service. Systems using Http4s versions before 0.23.35 or 1.0.0-M47 are at risk.

Compliance Impact

This vulnerability primarily impacts system availability by causing denial of service through CPU exhaustion and unbounded memory growth. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged downtime could disrupt services handling personal or health data, potentially leading to compliance violations if critical systems become unavailable.

Mitigation Strategies

Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later to address the WebSocket frame transcoder issue. Remove or restrict access to WebSocket endpoints if immediate patching is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69210. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart