An ember server with HTTP/2 enabled (.withHttp2) does not enforce SETTINGSMAXCONCURRENTSTREAMS on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhausting the heap.
Impact
Unauthenticated remote denial of service (memory exhaustion) against any Ember server built .withHttp2. This is the resource-exhaustion class of the HTTP/2 "Rapid Reset" family (CVE-2023-44487).
The same unchecked allocation path is reachable on the client via server-initiated PUSHPROMISE frames, so a malicious or compromised server can exhaust an ember-client's heap the same way.
Preconditions
- Server: with .withHttp2 enabled. - Client: makes HTTP/2 requests to malicious or compromised sites. enablePush is not enforced.
Workarounds
- Disable HTTP/2 on EmberServerBuilder or EmberClientBuilder (default) - Client only: avoid HTTP/2 to untrusted servers until patched.