Product
The http4s Ember backend is vulnerable to a denial of service attack via HPACK bomb due to improper header size accounting, allowing remote attackers to trigger Java heap memory exhaustion.