THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9vwc-pc8p-253q (high) — Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

[GHSA] GHSA-9vwc-pc8p-253q (high) — Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

medgithub_advisoriesPublished 2026-09-15

GHSA-9vwc-pc8p-253q Severity: high CVE: CVE-2026-69203

Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS

An ember server with HTTP/2 enabled (`.withHttp2`) does not enforce `SETTINGS_MAX_CONCURRENT_STREAMS` on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9vwc-pc8p-253q