HTTP/1.1, HTTP/2 and Websocket client for Erlang/OTP.
Current section
4 Advisories
Jump to
Current section
4 Advisories
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43966.html
- https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
- https://github.com/ninenines/cowlib
- https://github.com/ninenines/cowlib/pull/163#issuecomment-4952645232
- https://github.com/ninenines/cowlib/pull/166#issuecomment-5067554701
- https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42
- https://nvd.nist.gov/vuln/detail/CVE-2026-43966
- https://osv.dev/vulnerability/EEF-CVE-2026-43966
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
Affected Versions
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
Affected Versions
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
78 174
yesterday
23 265
last 7 days
117 815
all time
14 340 600