CVE-2026-69218
Received Received - Intake

Heap Memory Exhaustion in Http4s via Unbounded HTTP/2 Headers

Vulnerability report for CVE-2026-69218, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent CONTINUATION fragments without a size bound. A remote peer can keep an incomplete block open and exhaust heap memory before request decoding, affecting an ember-server or ember-client configured with withHttp2. The remediation tracks accumulated size against SETTINGS_MAX_HEADER_LIST_SIZE derived from EmberServerBuilder.maxHeaderSize or EmberClientBuilder.maxResponseHeaderSize, sends GOAWAY when the limit is exceeded, and applies receiveHeadersTimeout to incomplete blocks. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ember ember-server to 1.0.0-M47 (exc)
ember ember-client to 1.0.0-M47 (exc)
http4s http4s to 1.0.0-M47 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Http4s affects HTTP/2 implementations in versions before 0.23.35 and 1.0.0-M47. When a HEADERS or PUSH_PROMISE frame is received without the END_HEADERS flag, the system buffers the header block and subsequent CONTINUATION fragments without a size limit. A remote attacker can exploit this to send large or numerous CONTINUATION frames, causing memory exhaustion before request decoding completes.

Detection Guidance

Monitor for memory exhaustion or connection timeouts in HTTP/2 traffic. Check for incomplete header blocks in logs. Use tools like Wireshark to inspect HTTP/2 frames for missing END_HEADERS flags. Verify if your http4s version is below 0.23.35 or 1.0.0-M47.

Impact Analysis

This vulnerability can lead to denial-of-service conditions by exhausting server or client memory. It affects both servers and clients using HTTP/2 in affected versions. Memory exhaustion occurs before request decoding, potentially crashing applications or making them unresponsive.

Compliance Impact

This vulnerability primarily impacts system availability due to memory exhaustion, which could lead to service disruptions. While not directly violating GDPR or HIPAA, such disruptions may affect data processing operations subject to these regulations. GDPR requires ensuring availability of personal data processing systems, and HIPAA mandates safeguards against unauthorized access or disruptions. A denial-of-service condition could compromise these requirements.

Mitigation Strategies

Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later. Disable HTTP/2 if not required. Place Ember behind a reverse proxy that terminates HTTP/2. Monitor for unusual memory usage or connection drops.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69218. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart