Current section

3 Advisories

Jump to
EEF-CVE-2026-65624 CVE-2026-65624

Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion

July 28, 2026
CVSS
?
6.9 / 10.0 Medium
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Versions

>= 2.0.0-pre.4 and < 2.18.0

Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy

May 13, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 20K 40K 60K 80K

this version

0

yesterday

70 935

last 7 days

357 645

all time

149 843 636

Last Updated

Oct 08, 2026

License

ISC

Build Tools

make rebar3

Publisher

essen essen