{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/http4s-ember-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["http4s-ember-core"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["http4s"],"content_html":"\u003cp\u003eThe http4s Ember backend contains a vulnerability in its HTTP/2 implementation involving the handling of HPACK-compressed headers. Specifically, the implementation concatenates header and continuation frames before decoding, but fails to account for indexed headers within the configured maximum header size limit. An attacker can exploit this by sending specially crafted, compact HTTP/2 header packets that expand into significantly larger data structures during the decoding process. This malicious payload forces the application to allocate substantial memory, leading to an OutOfMemory (OOM) error. Observed in testing, approximately five concurrent connections against a 2GB heap are sufficient to crash the server. This vulnerability, identified as CVE-2026-54556, affects http4s versions up to 0.23.34 and 1.0.0-M46 across various Scala binary versions. Because no existing configuration can mitigate this while keeping HTTP/2 enabled, immediate action is required.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes multiple concurrent TCP connections to an http4s server or client utilizing the Ember backend.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP/2 session over these established connections.\u003c/li\u003e\n\u003cli\u003eAttacker sends a series of malicious HPACK-compressed header and continuation frames designed to bypass internal accounting mechanisms.\u003c/li\u003e\n\u003cli\u003eThe Hpack wrapper in the Ember core concatenates these frames without verifying against the effective maximum header size limit.\u003c/li\u003e\n\u003cli\u003eThe application attempts to decode the malicious payload into a large list object in the JVM memory space.\u003c/li\u003e\n\u003cli\u003eThe memory allocation exceeds the allocated Java heap space.\u003c/li\u003e\n\u003cli\u003eThe application service crashes with a java.lang.OutOfMemoryError, resulting in a denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial of service for affected http4s servers and clients. The vulnerability allows unauthenticated remote attackers to crash instances with relatively low request volume, potentially impacting any environment running http4s services exposed to untrusted traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDisable HTTP/2 support in all http4s Ember configurations immediately until a patched version is deployed.\u003c/li\u003e\n\u003cli\u003eMonitor application server logs for recurrent \u003ccode\u003ejava.lang.OutOfMemoryError\u003c/code\u003e exceptions that correlate with HTTP/2 traffic patterns to identify active exploitation attempts.\u003c/li\u003e\n\u003cli\u003eAudit all internet-facing services to identify and isolate instances running http4s versions 0.23.34 or earlier and 1.0.0 versions prior to M46.\u003c/li\u003e\n\u003cli\u003ePrioritize updating to the vendor-provided patch once the fix threading the maxHeaderSize into the Hpack decoding logic is applied to your specific environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T14:19:57Z","date_published":"2026-08-26T14:19:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-http4s-hpack-bomb/","summary":"The http4s Ember backend is vulnerable to a denial of service attack via HPACK bomb due to improper header size accounting, allowing remote attackers to trigger Java heap memory exhaustion.","title":"http4s Ember Backend HTTP/2 HPACK Bomb Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-08-http4s-hpack-bomb/"}],"language":"en","title":"CraftedSignal Threat Feed - Http4s-Ember-Core","version":"https://jsonfeed.org/version/1.1"}