CVE-2026-69210: Http4s: WebSocket decoder accepts negative length, causing infinite decode loop

Published Sep 15, 2026
·
Updated

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAXVALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop then runs indefinitely, pins a worker at full CPU, and grows an ArrayBuffer without bound, resulting in denial of service. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

Affected Software

2 affected components
Http4s Http4s<=0.23.35, >0.23.35<1.0.0-M47
Http4s Http4s>0.23.35<1.0.0-M47

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade http4s WebSocket FrameTranscoder/decoder to a version that resolves this vulnerability.

    Fixed in 0.23.35
  2. Upgrade

    Upgrade http4s WebSocket FrameTranscoder/decoder to a version that resolves this vulnerability.

    Fixed in 1.0.0-M47

Event History

Sep 15, 2026
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial of service?

Deployments using an Ember server with affected Http4s versions are exposed when they accept WebSocket connections. A remote client can trigger the issue after completing a WebSocket handshake.

2

Does exploiting this issue require authentication or user interaction?

No. The supplied severity vector indicates network access with low attack complexity, no privileges required, and no user interaction.

3

What is the impact of a successful attack?

The WebSocket decoder can enter an infinite loop that pins a worker at full CPU and grows an ArrayBuffer without bound, causing denial of service.

4

Which versions contain the fix?

The issue is fixed in Http4s versions 0.23.35 and 1.0.0-M47.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203