THREAT OPS › Threat News › [GHSA] GHSA-cp4q-fqw9-4hf6 (high) — Http4s Ember HTTP/2: unbounded continuation frame accumulation
[GHSA] GHSA-cp4q-fqw9-4hf6 (high) — Http4s Ember HTTP/2: unbounded continuation frame accumulation
GHSA-cp4q-fqw9-4hf6 Severity: high CVE: CVE-2026-69218
Http4s Ember HTTP/2: unbounded continuation frame accumulation
When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for subsequent `CONTINUATION` frames. These accumulate unbounded until the connection closes.
### Impact
A remote, unauthenticated pe
Indicators of compromise
- CVE-2026-69218cve
Original source: https://github.com/advisories/GHSA-cp4q-fqw9-4hf6