{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahttp4shttp4s_ember_server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:http4s:http4s_ember_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-69208"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["http4s-ember-server (\u003c= 0.23.34, 1.0.0-M1 \u003c= 1.0.0-M46)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["http4s"],"content_html":"\u003cp\u003eThe http4s \u003ccode\u003eDigestAuth\u003c/code\u003e server middleware contains a vulnerability in its stale-nonce cleanup mechanism, documented as CVE-2026-69208. The logic responsible for removing stale nonces uses an inverted comparison, resulting in the removal of fresh nonces while retaining stale ones indefinitely. Since the middleware generates a new nonce for every unauthenticated challenge, an attacker can intentionally flood a vulnerable service with requests to populate the nonce map. Because the stale nonces are never properly evicted, the map grows without bound until the Java Virtual Machine (JVM) experiences heap exhaustion and terminates due to an OutOfMemoryError. This vulnerability affects multiple versions of \u003ccode\u003ehttp4s-ember-server\u003c/code\u003e, including the 0.23.x series up to and including 0.23.34 and the 1.0.0 milestone series from 1.0.0-M1 through 1.0.0-M46. Organizations using DigestAuth should prioritize upgrading to the patched versions where the eviction logic has been corrected and a hard cache limit has been implemented.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition for the affected JVM process. This vulnerability impacts any service utilizing \u003ccode\u003eDigestAuth\u003c/code\u003e on its routes, potentially leading to widespread service unavailability if the application is targeted by high-volume, unauthenticated request bursts. Given the nature of the heap exhaustion, the leak is persistent and cannot be self-corrected by the application, requiring manual intervention or restarts to restore service until a patch is applied.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ehttp4s-ember-server\u003c/code\u003e to the latest version where the cache eviction logic is corrected and the 1,000,000 entry limit is imposed.\u003c/li\u003e\n\u003cli\u003eImplement a rate limiter in front of all routes protected by \u003ccode\u003eDigestAuth\u003c/code\u003e to mitigate the speed at which the nonce map can be filled while transitioning to patched versions.\u003c/li\u003e\n\u003cli\u003eConfigure monitoring for JVM heap utilization to identify early indicators of memory growth associated with nonce map exhaustion.\u003c/li\u003e\n\u003cli\u003eReview application configurations to ensure that \u003ccode\u003eDigestAuth\u003c/code\u003e is only applied to routes that require authentication.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T01:05:52Z","date_published":"2026-09-16T01:05:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-http4s-digestauth-dos/","summary":"An improper eviction logic in the http4s DigestAuth middleware allows unauthenticated remote attackers to cause heap exhaustion and service failure by triggering unbounded growth of the internal nonce map.","title":"Denial of Service via Heap Exhaustion in http4s DigestAuth","url":"https://feed.craftedsignal.io/briefs/2026-09-http4s-digestauth-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:http4s:http4s_ember_server:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}