THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gq9p-f254-h286 (high) — Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE

[GHSA] GHSA-gq9p-f254-h286 (high) — Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE

medgithub_advisoriesPublished 2026-09-15

GHSA-gq9p-f254-h286 Severity: high CVE: CVE-2026-88975

Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE

### Summary An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 MiB of a single frame in memory on a connection where Ember advertised a 16 KiB limit. The declared length is readable from the frame's first 9 bytes, but it is not comp

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gq9p-f254-h286