http4s-ember-core_3 is vulnerable to Denial of Service (DoS)
75
High Risk
The Ember HTTP/2 read loop reads frames from the socket with no idle timeout applied to the read itself. A peer that establishes an HTTP/2 connection (cleartext or TLS via ALPN) and then sends nothing keeps the connection open indefinitely. Enough such silent connections fill the pooled maxConnections slots and deny service to legitimate clients. The fix enforces an idle timeout on HTTP/2 socket reads.
You are affected if you are using a version that falls within the vulnerable range and you have enabled HTTP/2 on the Ember backend.
http4s-ember-core_3 is vulnerable to Denial of Service (DoS) in versions 0.23.12 - 0.23.36.
Upgrade the org.http4s:http4s-ember-core_3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.