{"id":"CVE-2026-69209","title":"Http4s is a Scala interface for HTTP services","summary":"Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts dec…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"http4s","product":"http4s","affected":["http4s < 0.23.35","http4s >= 1.0.0-M1, < 1.0.0-M47"],"published":"2026-09-15","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:39:16.610","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69209","references":[{"url":"https://github.com/http4s/http4s/commit/d578c3c9da6193627d40fa785e612cda7fcd77b3","label":"security-advisories@github.com"},{"url":"https://github.com/http4s/http4s/releases/tag/v0.23.35","label":"security-advisories@github.com"},{"url":"https://github.com/http4s/http4s/releases/tag/v1.0.0-M47","label":"security-advisories@github.com"},{"url":"https://github.com/http4s/http4s/security/advisories/GHSA-jrxx-w2m8-5hf5","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-16T18:25:00.686488Z"},"ingestedAt":"2026-09-15T19:42:58.803Z","epss":0.0035,"epssPercentile":0.28635,"slug":"CVE-2026-69209","body":"## Overview\n\nHttp4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket handshake against an http4s-blaze-server or http4s-ember-server endpoint can exhaust server memory with oversized frames or fragmented messages. The patched decoder applies a configurable 64 MiB default limit to individual frames and defragmented messages through EmberServerBuilder.withMaxWebSocketMessageSize. This issue is fixed in versions 0.23.35 and 1.0.0-M47.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}