CVE-2026-69203: HTTP4S
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connection can open an unbounded number of streams, each retaining per-stream state until heap exhaustion. The same unchecked allocation is reachable in an ember-client through server-initiated PUSH_PROMISE frames because enablePush is not enforced. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Affected products
- HTTP4S HTTP4S: before 0.23.35 (fixed in 0.23.35); from 1.0.0-M1, before 1.0.0-M47 (fixed in 1.0.0-M47)
Published 2026-09-15. Last modified 2026-09-16.