GHSA-9vwc-pc8p-253q

Suggest an improvement
Source
https://github.com/advisories/GHSA-9vwc-pc8p-253q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9vwc-pc8p-253q
Aliases
  • CVE-2026-69203
Published
2026-09-15T19:53:14Z
Modified
2026-09-15T20:00:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
Details

An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGS_MAX_CONCURRENT_STREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.

Impact

Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).

The same unchecked allocation path is reachable on the client via server-initiated PUSH_PROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.

Preconditions

  • Server: with .withHttp2 enabled.
  • Client: makes HTTP/2 requests to malicious or compromised sites. enablePush is not enforced.

Workarounds

  • Disable HTTP/2 on EmberServerBuilder or EmberClientBuilder (default)
  • Client only: avoid HTTP/2 to untrusted servers until patched.
Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-15T19:53:14Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Maven
org.http4s:http4s-ember-core_2.12

Package

Name
org.http4s:http4s-ember-core_2.12
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-ember-core_2.12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.10.0-M10
0.21.0-M2
0.21.0-M3
0.21.0-M4
0.21.0-M5
0.21.0-M6
0.21.0-RC1
0.21.0-RC2
0.21.0-RC3
0.21.0-RC4
0.21.0-RC5
0.21.0
0.21.1
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.17
0.21.18
0.21.19
0.21.20
0.21.21
0.21.22
0.21.23
0.21.24
0.21.25
0.21.26
0.21.27
0.21.28
0.21.29
0.21.30
0.21.31
0.21.32
0.21.33
0.21.34
0.22.0-M1
0.22.0-M2
0.22.0-M3
0.22.0-M4
0.22.0-M5
0.22.0-M6
0.22.0-M7
0.22.0-M8
0.22.0-RC1
0.22.0
0.22-53-01128f5
0.22-96-55d3184
0.22-129-24d065b
0.22-143-49b5a8d
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json"
org.http4s:http4s-ember-core_2.13

Package

Name
org.http4s:http4s-ember-core_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-ember-core_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.10.0-M10
0.21.0-M2
0.21.0-M3
0.21.0-M4
0.21.0-M5
0.21.0-M6
0.21.0-RC1
0.21.0-RC2
0.21.0-RC3
0.21.0-RC4
0.21.0-RC5
0.21.0
0.21.1
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.17
0.21.18
0.21.19
0.21.20
0.21.21
0.21.22
0.21.23
0.21.24
0.21.25
0.21.26
0.21.27
0.21.28
0.21.29
0.21.30
0.21.31
0.21.32
0.21.33
0.21.34
0.22.0-M1
0.22.0-M2
0.22.0-M3
0.22.0-M4
0.22.0-M5
0.22.0-M6
0.22.0-M7
0.22.0-M8
0.22.0-RC1
0.22.0
0.22-53-01128f5
0.22-96-55d3184
0.22-129-24d065b
0.22-143-49b5a8d
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json"
org.http4s:http4s-ember-core_3

Package

Name
org.http4s:http4s-ember-core_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-ember-core_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.22.0-M8
0.22.0-RC1
0.22.0
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json"
org.http4s:http4s-ember-core_2.13

Package

Name
org.http4s:http4s-ember-core_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-ember-core_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M47

Affected versions

1.*
1.0.0-M2
1.0.0-M3
1.0.0-M4
1.0.0-M5
1.0.0-M6
1.0.0-M7
1.0.0-M8
1.0.0-M9
1.0.0-M10
1.0.0-M11
1.0.0-M13
1.0.0-M14
1.0.0-M15
1.0.0-M16
1.0.0-M17
1.0.0-M18
1.0.0-M19
1.0.0-M20
1.0.0-M21
1.0.0-M22
1.0.0-M23
1.0.0-M24
1.0.0-M25
1.0.0-M27
1.0.0-M28
1.0.0-M29
1.0.0-M30
1.0.0-M31
1.0.0-M32
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41
1.0.0-M42
1.0.0-M43
1.0.0-M44
1.0.0-M45
1.0.0-M46

Database specific

last_known_affected_version_range
"<= 1.0.0-M46"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json"
org.http4s:http4s-ember-core_3

Package

Name
org.http4s:http4s-ember-core_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-ember-core_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M47

Affected versions

1.*
1.0.0-M22
1.0.0-M23
1.0.0-M24
1.0.0-M25
1.0.0-M27
1.0.0-M28
1.0.0-M29
1.0.0-M30
1.0.0-M31
1.0.0-M32
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41
1.0.0-M42
1.0.0-M43
1.0.0-M44
1.0.0-M45
1.0.0-M46

Database specific

last_known_affected_version_range
"<= 1.0.0-M46"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vwc-pc8p-253q/GHSA-9vwc-pc8p-253q.json"