Current section

6 Advisories

Jump to
EEF-CVE-2026-59248 CVE-2026-59248

Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS

July 28, 2026
CVSS
?
8.7 / 10.0 High
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Versions

>= 2.0.0-pre.1 and < 2.19.0
EEF-CVE-2026-43966 CVE-2026-43966 GHSA-w4f7-4cxr-rv3c

HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

June 08, 2026

Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame

May 13, 2026

Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS

May 11, 2026

CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1

May 11, 2026

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

May 11, 2026

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 20K 40K 60K 80K

this version

77 292

yesterday

16 914

last 7 days

341 952

all time

102 429 191

Last Updated

Jul 28, 2026

License

ISC

Build Tools

make rebar3

Publisher

essen essen