THREAT OPS › Threat News › [GHSA] GHSA-9vwc-pc8p-253q (high) — Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
[GHSA] GHSA-9vwc-pc8p-253q (high) — Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
GHSA-9vwc-pc8p-253q Severity: high CVE: CVE-2026-69203
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
An ember server with HTTP/2 enabled (`.withHttp2`) does not enforce `SETTINGS_MAX_CONCURRENT_STREAMS` on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that
Indicators of compromise
- CVE-2026-69203cve
- CVE-2023-44487cve
Original source: https://github.com/advisories/GHSA-9vwc-pc8p-253q