Current section
3 Advisories
Jump to
Current section
3 Advisories
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
Affected Versions
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43966.html
- https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/pull/163#issuecomment-4952645232
- https://github.com/ninenines/cowlib/pull/166#issuecomment-5067554701
- https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42
- https://nvd.nist.gov/vuln/detail/CVE-2026-43966
- https://osv.dev/vulnerability/EEF-CVE-2026-43966
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
Affected Versions
References
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
385 482
yesterday
69 477
last 7 days
352 929
all time
149 772 701