Intel

AIKIDO-2026-66258

http4s-ember-core_3 is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-3jm4-mm2v-96qj Published Today

75

High Risk

This Affects:

JAVAhttp4s-ember-core_3
0.23.12 - 0.23.36
Fixed in 0.23.37
Are you affected? Scan for Free

TL;DR

The Ember HTTP/2 read loop reads frames from the socket with no idle timeout applied to the read itself. A peer that establishes an HTTP/2 connection (cleartext or TLS via ALPN) and then sends nothing keeps the connection open indefinitely. Enough such silent connections fill the pooled maxConnections slots and deny service to legitimate clients. The fix enforces an idle timeout on HTTP/2 socket reads.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have enabled HTTP/2 on the Ember backend.

Background info

http4s-ember-core_3 is vulnerable to Denial of Service (DoS) in versions 0.23.12 - 0.23.36.

How to fix this

Upgrade the org.http4s:http4s-ember-core_3 library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform