http4s-ember-core_3 is vulnerable to Denial of Service (DoS)
82
High Risk
The Ember HTTP/2 header accumulation enforces maxHeaderBlockSize while gathering CONTINUATION frames, but a CONTINUATION frame carrying END_HEADERS bypasses that size check. A peer sends a small HEADERS frame followed by an oversized END_HEADERS CONTINUATION frame, up to about 16 MiB, exceeding the roughly 65 KiB header-block limit by about 256x. The oversized block is buffered and decoded, exhausting server memory, and it defeats an earlier size-limit fix. The patch applies the size check to the terminating CONTINUATION frame.
You are affected if you are using a version that falls within the vulnerable range and you have enabled HTTP/2 on the Ember backend.
http4s-ember-core_3 is vulnerable to Denial of Service (DoS) in versions 0.23.35 - 0.23.36.
Upgrade the org.http4s:http4s-ember-core_3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.