THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cp4q-fqw9-4hf6 (high) — Http4s Ember HTTP/2: unbounded continuation frame accumulation

[GHSA] GHSA-cp4q-fqw9-4hf6 (high) — Http4s Ember HTTP/2: unbounded continuation frame accumulation

medgithub_advisoriesPublished 2026-09-15

GHSA-cp4q-fqw9-4hf6 Severity: high CVE: CVE-2026-69218

Http4s Ember HTTP/2: unbounded continuation frame accumulation

When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for subsequent `CONTINUATION` frames. These accumulate unbounded until the connection closes.

### Impact

A remote, unauthenticated pe

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cp4q-fqw9-4hf6