THREAT OPS › Threat News › [GHSA] GHSA-8f3q-3jmv-7prw (high) — Http4s Ember HTTP/2 has an unbounded outbound frame queue
[GHSA] GHSA-8f3q-3jmv-7prw (high) — Http4s Ember HTTP/2 has an unbounded outbound frame queue
GHSA-8f3q-3jmv-7prw Severity: high CVE: CVE-2026-69213
Http4s Ember HTTP/2 has an unbounded outbound frame queue
Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because
Indicators of compromise
- CVE-2026-69213cve
Original source: https://github.com/advisories/GHSA-8f3q-3jmv-7prw