Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket handshake against an http4s-blaze-server or http4s-ember-server endpoint can exhaust server memory with oversized frames or fragmented messages. The patched decoder applies a configurable 64 MiB default limit to individual frames and defragmented messages through EmberServerBuilder.withMaxWebSocketMessageSize. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 19:17
Updated : 2026-09-15 19:17
NVD link : CVE-2026-69209
Mitre link : CVE-2026-69209
CVE.ORG link : CVE-2026-69209
JSON object : View
Products Affected
No product.
