Current section
3 Advisories
Jump to
Current section
3 Advisories
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
Affected Versions
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43966.html
- https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/pull/163#issuecomment-4952645232
- https://github.com/ninenines/cowlib/pull/166#issuecomment-5067554701
- https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42
- https://nvd.nist.gov/vuln/detail/CVE-2026-43966
- https://osv.dev/vulnerability/EEF-CVE-2026-43966
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
Affected Versions
References
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
0
yesterday
70 935
last 7 days
357 645
all time
149 843 636