THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6m4x-pp6q-5jmm (high) — Http4s Ember HTTP/2: unbounded inbound body buffering

[GHSA] GHSA-6m4x-pp6q-5jmm (high) — Http4s Ember HTTP/2: unbounded inbound body buffering

medgithub_advisoriesPublished 2026-09-15

GHSA-6m4x-pp6q-5jmm Severity: high CVE: CVE-2026-69202

Http4s Ember HTTP/2: unbounded inbound body buffering

Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore provides no backpressure: a peer can stream a large or unbou

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6m4x-pp6q-5jmm