{"id":"CVE-2026-88975","summary":"Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE","details":"Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised 16 KiB and either complete or slowly stream it, causing up to 1024-fold memory amplification per connection before processFrame can reject the frame. The shared H2Connection.readLoop affects withHttp2 servers and clients, while HTTP/2-disabled configurations are unaffected, and the patch rejects oversized frames before buffering their payloads. This issue is fixed in versions 0.23.37 and 1.0.0-M48.","aliases":["GHSA-gq9p-f254-h286"],"modified":"2026-09-18T03:31:01.557818561Z","published":"2026-09-15T19:31:25.221Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88975.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v0.23.37"},{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v1.0.0-M48"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88975.json"},{"type":"ADVISORY","url":"https://github.com/http4s/http4s/security/advisories/GHSA-gq9p-f254-h286"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88975"},{"type":"FIX","url":"https://github.com/http4s/http4s/commit/87cf334fa3f608ef7d3eb359e71e037ba3336d29"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/http4s/http4s","events":[{"introduced":"0"},{"introduced":"756ce63aee681c5b632bbeafe0b8fde2f3d237f4"},{"fixed":"73340be10836b95241ed2d7682b4da057b7b5ccb"},{"fixed":"2d62cbe12e8941ac4800a41fa45e132900b90caa"},{"fixed":"87cf334fa3f608ef7d3eb359e71e037ba3336d29"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.23.37"},{"introduced":"1.0.0-M1"},{"fixed":"1.0.0-M48"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.23.36","v1.0.0-M46","v0.23.34","v0.23.33","v1.0.0-M45","v0.23.32","v0.23.31","v1.0.0-M44","v0.23.30","v1.0.0-M43","v1.0.0-M42","v0.23.29","v0.23.28","v0.23.27","v1.0.0-M41","v0.23.26","v0.23.25","v0.23.24","v0.23.23","v1.0.0-M40","v0.23.22","v0.23.20","v0.23.19","v0.23.19-RC2","v0.23.19-RC1","v1.0.0-M39","v0.23.18","v1.0.0-M37","v0.23.16","v1.0.0-M36","v0.23.15","v1.0.0-M35","v0.23.14","v1.0.0-M34","v0.23.13","v1.0.0-M33","v0.23.12","v1.0.0-M32","v0.23.11","v1.0.0-M31","v0.23.10","v0.23.9","v0.23.8","v1.0.0-M30","v0.23.7","v1.0.0-M29","v0.23.6","v0.23.5","v1.0.0-M28","v0.23.3","v1.0.0-M26","v0.23.2","v1.0.0-M24","v0.23.1","v0.23.0","v1.0.0-M22","v0.23.0-M1","v1.0.0-M21","v1.0.0-M20","v1.0.0-M19","v1.0.0-M17","v1.0.0-M16","v1.0.0-M15","v1.0.0-M13","v1.0.0-M12","v1.0.0-M11","v1.0.0-M10","v1.0.0-M9","v1.0.0-M8","v1.0.0-M7","v1.0.0-M6","v1.0.0-M5","v1.0.0-M4","v1.0.0-M3","v1.0.0-M2","v1.0.0-M1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88975.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}