Support library for manipulating Web protocols.
Current section
4 Advisories
Jump to
Current section
4 Advisories
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
Affected Versions
References
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-7790.html
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369
- https://github.com/ninenines/cowlib/releases/tag/2.16.1
- https://hex.pm/packages/cowlib
- https://nvd.nist.gov/vuln/detail/CVE-2026-7790
- https://osv.dev/vulnerability/EEF-CVE-2026-7790
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43968.html
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/commit/6165fc40efa159ba1cceee7e7981e790acba5d9c
- https://github.com/ninenines/cowlib/releases/tag/2.16.1
- https://hex.pm/packages/cowlib
- https://nvd.nist.gov/vuln/detail/CVE-2026-43968
- https://osv.dev/vulnerability/EEF-CVE-2026-43968
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Affected Versions
References
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
258 994
yesterday
12 576
last 7 days
279 127
all time
99 649 103