An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGS_MAX_CONCURRENT_STREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.
Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).
The same unchecked allocation path is reachable on the client via server-initiated PUSH_PROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.
.withHttp2 enabled.enablePush is not enforced.EmberServerBuilder or EmberClientBuilder (default){
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-15T19:53:14Z",
"nvd_published_at": null,
"severity": "HIGH"
}