THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8f3q-3jmv-7prw (high) — Http4s Ember HTTP/2 has an unbounded outbound frame queue

[GHSA] GHSA-8f3q-3jmv-7prw (high) — Http4s Ember HTTP/2 has an unbounded outbound frame queue

medgithub_advisoriesPublished 2026-09-15

GHSA-8f3q-3jmv-7prw Severity: high CVE: CVE-2026-69213

Http4s Ember HTTP/2 has an unbounded outbound frame queue

Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8f3q-3jmv-7prw