Vulnerability GHSA-6m4x-pp6q-5jmm

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
September 15, 2026 at 07:52 PM UTC
Http4s Ember HTTP/2: unbounded inbound body buffering
0.10.0
0.10.0

Summary

Http4s Ember HTTP/2: unbounded inbound body buffering

Details

Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore provides no backpressure: a peer can stream a large or unbounded body faster than the application drains it and the connection retains every payload in heap.

This is the read-path mirror of the outbound queue issue.

This affects an Ember receiving a request body and an Ember client receiving a response body from a hostile server.

Impact

Unauthenticated remote denial of service (OOM) against any Ember server built .withHttp2 for a non-draining or slow-draining route, and against an Ember client consuming from a hostile or compromised server.

Workarounds

  • Disable HTTP/2 to remove the vector entirely.
  • Apply an aggregate request-entity size limit (e.g. EntityLimiter middleware) on routes that consume the body.
  • Ensure handlers fully drain request bodies with aggressive idle timeouts.

Timeline

Published
3 hours ago
September 15, 2026 at 07:52 PM UTC
Fixed (0.23.35)
Unknown
Unknown
Fixed (0.23.35)
Unknown
Unknown
Fixed (1.0.0-M47)
Unknown
Unknown
Fixed (0.23.35)
Unknown
Unknown
Fixed (1.0.0-M47)
Unknown
Unknown
Last Modified
3 hours ago
September 15, 2026 at 08:00 PM UTC