THREAT OPS › Threat News › [GHSA] GHSA-6m4x-pp6q-5jmm (high) — Http4s Ember HTTP/2: unbounded inbound body buffering
[GHSA] GHSA-6m4x-pp6q-5jmm (high) — Http4s Ember HTTP/2: unbounded inbound body buffering
GHSA-6m4x-pp6q-5jmm Severity: high CVE: CVE-2026-69202
Http4s Ember HTTP/2: unbounded inbound body buffering
Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore provides no backpressure: a peer can stream a large or unbou
Indicators of compromise
- CVE-2026-69202cve
Original source: https://github.com/advisories/GHSA-6m4x-pp6q-5jmm