Description
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop then runs indefinitely, pins a worker at full CPU, and grows an ArrayBuffer without bound, resulting in denial of service. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because Http4s' WebSocket FrameTranscoder accepts a negative 64‑bit payload length. When a client completes a WebSocket handshake with an Ember server and sends a frame with this negative length, the decoder returns an empty frame without consuming input. The decoding loop then executes indefinitely, tying up CPU and repeatedly appending to an ArrayBuffer until it grows without bound, which leads to denial of service. This flaw is identified by the weakness of an infinite loop (CWE‑835) coupled with improper handling of negative values (CWE‑1284), resulting in a logic error in the decoder’s length validation. An attacker only needs to initiate a WebSocket connection to an Ember server that hosts http4s and transmit a specially crafted frame with a negative length. The resulting resource exhaustion renders the HTTP service unavailable, with no data compromise.

Affected Systems

Deployments that use the http4s Scala HTTP interface and support WebSocket connections are affected, specifically all versions prior to 0.23.35 and 1.0‑M47. The vulnerability can be triggered by a remote client that completes a WebSocket handshake through an Ember server and sends such a frame.

Risk and Exploitability

The CVSS score is 7.5. The EPSS score is < 1%, and KEV is not listed, which means the risk is primarily derived from the high severity rating. An attacker needs only to establish a WebSocket connection and send a frame with a negative length; no additional privileges are required.

Generated by OpenCVE AI on September 20, 2026 at 12:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade http4s to version 0.23.35 or later, or to 1.0.0-M47, to receive the fixed FrameTranscoder implementation.
  • If an immediate upgrade cannot be applied, temporarily disable WebSocket functionality or restrict WebSocket traffic to trusted IP addresses until a patch is deployed.
  • Continuously monitor CPU usage and internal buffer growth; a sudden increase in these metrics may indicate that the flaw is being exploited.

Generated by OpenCVE AI on September 20, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Http4s
Http4s http4s
Vendors & Products Http4s
Http4s http4s

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing the decoder to return an empty frame without advancing its input. The decode loop then runs indefinitely, pins a worker at full CPU, and grows an ArrayBuffer without bound, resulting in denial of service. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Title Http4s: WebSocket decoder accepts negative length, causing infinite decode loop
Weaknesses CWE-1284
CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:45:18.332Z

Reserved: 2026-08-03T16:57:50.124Z

Link: CVE-2026-69210

cve-icon Vulnrichment

Updated: 2026-09-17T16:45:14.152Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:17:40.320

Modified: 2026-09-17T17:16:46.500

Link: CVE-2026-69210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:45:17Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')