CVE-2026-54556:
Java Análisis y mitigación de vulnerabilidades
Vista general
CVE-2026-54556 is an HTTP/2 denial-of-service vulnerability in the http4s Ember backend, commonly referred to as an "HPACK bomb" attack. An unauthenticated remote peer can send a specially crafted, highly compressed HPACK header block that expands into a disproportionately large decoded representation held in memory, ultimately exhausting the JVM heap. Affected packages include org.http4s:http4s-ember-core_2.12, http4s-ember-core_2.13, and http4s-ember-core_3 in versions ≤ 0.23.34 and ≥ 1.0.0-M1 through < 1.0.0-M46. The vulnerability was originally published on July 6, 2026, and added to the GitHub Advisory Database on August 26, 2026. It carries a CVSS v4 base score of 8.2 (High) (Github Advisory).
Técnicas
The root cause is classified as CWE-409 (Improper Handling of Highly Compressed Data / Data Amplification). The vulnerable code resides in ember-core/shared/src/main/scala/org/http4s/ember/core/h2/Hpack.scala, where Ember concatenates HEADERS and CONTINUATION frame fragments and decodes them all at once into a single List. The maxHeaderSize accounting in the HPACK wrapper fails to include indexed headers or per-header HPACK overhead, allowing a small compressed header block to expand into a much larger decoded structure that is retained in memory for further processing. Because no configuration option short of disabling HTTP/2 could prevent the attack prior to the fix, approximately five concurrent malicious connections were sufficient to trigger an OutOfMemoryError: Java heap space on a JVM with a 2 GB heap (Github Advisory, Security Advisory). The fix threads the maxHeaderSize setting from the server/client builder into the HPACK decoder so connections are terminated once decoded data exceeds the configured limit (Patch Commit).
Impacto
Successful exploitation results in a complete denial of service for the affected http4s process: the JVM heap is exhausted, causing an OutOfMemoryError that crashes or renders the service unavailable. Both server-side deployments (http4s Ember servers exposed to untrusted HTTP/2 clients) and client-side deployments (http4s Ember clients directed to an untrusted HTTP/2 server) are affected. There is no confidentiality or integrity impact — the vulnerability is purely an availability issue with no known path to data exfiltration or lateral movement (Github Advisory).
Explotabilidad
No public proof-of-concept exploit code specific to http4s has been identified, and there is no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, the attack requires no authentication, no user interaction, and only a small number of concurrent connections (~5 against a 2 GB heap), making it straightforward to execute against any exposed Ember HTTP/2 endpoint (Github Advisory). The attack requirement of "Present" in the CVSS v4 vector reflects that HTTP/2 must be enabled on the target, which is a deployment condition rather than an active security control.
Pasos de explotación
- Reconnaissance: Identify internet-facing services built on http4s with the Ember backend and HTTP/2 enabled (e.g., via TLS ALPN negotiation advertising
h2, or HTTP/2 prior knowledge on plaintext endpoints). - Craft HPACK bomb payload: Construct a compressed HTTP/2 HEADERS frame containing a highly compressed HPACK header block — for example, using a large number of references to indexed headers that expand to many kilobytes or megabytes of decoded header data when inflated.
- Open concurrent connections: Establish multiple simultaneous HTTP/2 connections (approximately 5 connections against a 2 GB JVM heap) to the target server, each sending the crafted HEADERS frame.
- Trigger memory exhaustion: Each connection causes the Ember HPACK decoder to expand and hold the inflated header list in memory. With enough concurrent connections, the cumulative decoded data exhausts the JVM heap, resulting in
java.lang.OutOfMemoryError: Java heap spaceand a service crash or hang (Github Advisory, Security Advisory).
Indicadores de compromiso
- Logs: JVM crash logs or application logs containing
java.lang.OutOfMemoryError: Java heap spacewith stack traces referencingscala.collection.mutable.ListBuffer,org.http4s.ember.core.h2.H2Stream.receiveHeaders, ororg.http4s.ember.core.h2.PseudoHeaders. - Network: A burst of simultaneous inbound HTTP/2 connections (TLS ALPN
h2) from one or more source IPs, each sending HEADERS frames with unusually small wire-size payloads that do not correspond to typical application traffic. - Process: Sudden spike in JVM heap usage visible in JMX/metrics dashboards, followed by process termination or GC thrashing; heap dumps showing large
scala.collection.immutable.ListorListBufferinstances inorg.http4s.ember.core.h2classes. - System: Unexpected service restarts or container/pod OOMKill events in orchestration platforms (e.g., Kubernetes OOMKilled exit code 137) coinciding with HTTP/2 traffic spikes (Github Advisory).
Mitigación y soluciones alternativas
Upgrade to http4s 0.23.35 (for the 0.23.x series) or 1.0.0-M47 (for the 1.0.x milestone series), which enforce the maxHeaderSize limit correctly within the HPACK decoder and terminate connections that exceed it (v0.23.35 Release, v1.0.0-M47 Release). For deployments that cannot upgrade immediately, the only available workaround is to disable HTTP/2 in the Ember backend entirely (Github Advisory). No other configuration option in pre-fix versions can prevent this attack.
Reacciones de la comunidad
The advisory was authored by maintainer rossabaker (Ross A. Baker) and credited reardonj as the reporter and ERobertGII for security analysis and mitigations, indicating the issue was discovered through independent security scans rather than active exploitation reports (v0.23.35 Release). The 0.23.35 release was described as a "security hardening release" addressing 18 separate security advisories simultaneously, suggesting a coordinated internal audit. No significant broader media coverage or notable external researcher commentary has been identified beyond the official advisory.
Recursos adicionales
Fuente: Este informe se generó utilizando IA
Relacionado Java Vulnerabilidades:
Evaluación gratuita de vulnerabilidades
Compare su postura de seguridad en la nube
Evalúe sus prácticas de seguridad en la nube en 9 dominios de seguridad para comparar su nivel de riesgo e identificar brechas en sus defensas.
Recursos adicionales de Wiz
Obtén una demostración personalizada
¿Listo para ver a Wiz en acción?
"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."