GHSA-gq9p-f254-h286: High severity maven/org.http4s:http4s-ember-core_3 vulnerability
Summary An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 MiB of a single frame in memory on a connection where Ember advertised a 16 KiB limit. The declared length is readable from the frame's first 9 bytes, but it is not compared against SETTINGSMAXFRAMESIZE until the whole payload has been read into a contiguous buffer. That is 1024x amplification per connection, bounded by the protocol's 24-bit length field rather than by any setting, and at the default maxConnections of 1024 it puts about 16 GiB of heap in reach.
Details H2Frame.RawFrame.fromByteVector (ember-core/.../h2/H2Frame.scala:66-69) reads the length, then refuses to produce a frame until 9 + length bytes are present:
val length = (bv(2) & 0xff) | ((bv(1) & 0xff) << 8) | ((bv(0) & 0xff) << 16) if (bv.length >= 9 + length) {
readNextFrame in H2Connection.readLoop (H2Connection.scala:246-266) reads that None as "need more" and concatenates further socket reads into one accumulator until it is satisfied.
The only check of an inbound frame against the connection's own SETTINGSMAXFRAMESIZE is in processFrame at H2Connection.scala:534, which cannot run until the frame is assembled. So the value that condemns the frame sits in the accumulator from byte 9 onward and is never consulted. A peer that declares 16777215 and dribbles the payload without finishing gets the same buffering with no reaction at all, since an incomplete frame never reaches processFrame.
RFC 9113 4.2 requires treating an oversized frame as a connection error and explicitly permits responding without reading the rest of the payload.
Impact Uncontrolled resource consumption leading to unauthenticated remote denial of service by memory exhaustion.
- ember-server built .withHttp2: any peer able to open an HTTP/2 connection can trigger it. No authentication and no valid request, since the frame is rejected before it is associated with a stream, and the incomplete variant is never rejected. - ember-client built .withHttp2 against a hostile origin: readLoop is shared, so the client side is symmetric. Reasoned from the shared code path, not reproduced. - Not affected: HTTP/2 off, which is the default on both builders.
The overshoot is not configurable. It comes from the protocol's length field, not from Ember's limit, so tuning SETTINGSMAXFRAMESIZE down does not reduce exposure, and withIdleTimeout does not apply because the read loop is making steady progress. Workarounds: leave HTTP/2 off, or terminate it at a proxy that enforces frame size and speak HTTP/1.1 to Ember.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.http4s:http4s-ember-core_3to a version that resolves this vulnerability.Fixed in 1.0.0-M48 - Upgrade
Upgrade
maven/org.http4s:http4s-ember-core_2.13to a version that resolves this vulnerability.Fixed in 1.0.0-M48 - Upgrade
Upgrade
maven/org.http4s:http4s-ember-core_3to a version that resolves this vulnerability.Fixed in 0.23.37 - Upgrade
Upgrade
maven/org.http4s:http4s-ember-core_2.12to a version that resolves this vulnerability.Fixed in 0.23.37 - Upgrade
Upgrade
maven/org.http4s:http4s-ember-core_2.13to a version that resolves this vulnerability.Fixed in 0.23.37 - Compensating control
Leave HTTP/2 off (the builders default to HTTP/2 off, and turning it off prevents the Ember HTTP/2 read loop buffering issue).
- Compensating control
Terminate HTTP/2 at a proxy that enforces HTTP/2 frame size limits, and have the proxy speak HTTP/1.1 to Ember.
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using Ember's HTTP/2 read loop are exposed. The issue applies even when Ember advertises a 16 KiB maximum frame size, because that limit is checked only after the full inbound frame has been buffered.
What does an attacker need to exploit this?
An attacker only needs to act as an unauthenticated HTTP/2 peer and send a frame declaring a large payload length. The declared length is available in the first 9 bytes, but Ember continues accumulating payload data before enforcing the configured frame-size limit.
What is the potential resource impact?
A single connection can cause Ember to retain up to 16 MiB for one frame, a 1024x increase over the advertised 16 KiB limit. With the stated default maxConnections value of 1024, approximately 16 GiB of heap may be reachable.