Current section
3 Advisories
Jump to
Current section
3 Advisories
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
Affected Versions
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43966.html
- https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/pull/163#issuecomment-4952645232
- https://github.com/ninenines/cowlib/pull/166#issuecomment-5067554701
- https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42
- https://nvd.nist.gov/vuln/detail/CVE-2026-43966
- https://osv.dev/vulnerability/EEF-CVE-2026-43966
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
Affected Versions
References
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
105 817
yesterday
44 942
last 7 days
279 908
all time
146 868 340