PT-2026-92473 · Http4S · Http4S

CVE-2026-88975

·

Published

2026-09-15

·

Updated

2026-09-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Http4s versions prior to 0.23.37 Http4s versions prior to 1.0.0-M48
Description An issue exists in Ember's HTTP/2 read loop where the system parses a frame's 24-bit declared length but buffers the entire payload before comparing it with SETTINGS MAX FRAME SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised a 16 KiB limit and either complete or slowly stream it. This results in up to 1024-fold memory amplification per connection before the processFrame() function can reject the frame, potentially leading to remote denial of service via memory exhaustion. The issue affects both servers and clients configured with withHttp2, while configurations with HTTP/2 disabled are unaffected. The vulnerability is triggered within the H2Connection.readLoop and H2Frame.RawFrame.fromByteVector() logic.
Recommendations Update to version 0.23.37 or later. Update to version 1.0.0-M48 or later. Disable HTTP/2 if it is not required. Terminate HTTP/2 connections at a proxy that enforces frame size limits and communicate with Ember using HTTP/1.1.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88975
GHSA-GQ9P-F254-H286

Affected Products

Http4S