Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vmm3-xgcx-67hm | http4s has HTTP/2 Denial of Service with Ember Backend |
Wed, 26 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/src/main/scala/org/http4s/ember/core/h2/Hpack.scala concatenates HEADERS and CONTINUATION frame fragments and decodes them into a single List, but maxHeaderSize accounting does not include indexed headers or HPACK per-header overhead. A small compressed header block can therefore expand into a much larger decoded representation that remains in memory for processing. Servers exposed to untrusted HTTP/2 traffic and clients directed to an untrusted HTTP/2 server are affected, and concurrent malicious connections can exhaust the process heap. This issue is fixed in versions 0.23.35 and 1.0.0-M47. | |
| Title | Http4s: HTTP/2 Denial of Service with Ember Backend | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-26T14:10:22.349Z
Reserved: 2026-06-15T19:04:14.456Z
Link: CVE-2026-54556
No data.
Status : Received
Published: 2026-08-26T15:16:49.527
Modified: 2026-08-26T15:16:49.527
Link: CVE-2026-54556
No data.
OpenCVE Enrichment
Updated: 2026-08-26T16:45:08Z
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
Github GHSA