Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9vwc-pc8p-253q | Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS |
Tue, 15 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connection can open an unbounded number of streams, each retaining per-stream state until heap exhaustion. The same unchecked allocation is reachable in an ember-client through server-initiated PUSH_PROMISE frames because enablePush is not enforced. This issue is fixed in versions 0.23.35 and 1.0.0-M47. | |
| Title | Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMS | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T19:36:32.272Z
Reserved: 2026-08-03T16:57:50.124Z
Link: CVE-2026-69203
Updated: 2026-09-15T19:36:29.213Z
Status : Received
Published: 2026-09-15T20:17:39.120
Modified: 2026-09-15T20:17:39.120
Link: CVE-2026-69203
No data.
OpenCVE Enrichment
No data.
Github GHSA