Source: erlang-cowlib Version: 2.18.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for erlang-cowlib. CVE-2026-59248[0]: | Allocation of resources without limits vulnerability in ninenines | cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to | exhaust memory on the vulnerable server (or client) and cause a | denial of service. The HPACK and QPACK prefixed-integer decoder | cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl (invoked | from cow_hpack:decode/2 in src/cow_hpack.erl and from | cow_qpack:decode_field_section/3 in src/cow_qpack.erl) reads | continuation octets until it sees one whose high bit is clear, | evaluating Int + (Value bsl M) at each step with the shift M growing | by seven per octet. No limit is enforced on the number of | continuation octets, on the resulting bit width, or on the value; | the decoder consumes whatever encoded length the peer supplies. | Because Erlang integers are immutable, each intermediate Value bsl M | and each accumulator update allocates a fresh bignum whose digit | width grows linearly with the number of octets processed so far. | Summed across the whole decode, the transient bignum digit | materialization is on the order of the square of the encoded length. | A single maximal HPACK indexed representation carried inside one | HTTP/2 HEADERS plus one CONTINUATION frame at Cowboy's default | max_frame_size_received can force hundreds of megabytes of transient | allocation and garbage-collection churn before the resulting header- | table index is rejected as invalid. Repeated or concurrent | connections multiply the pressure and can drive the Erlang VM to | memory exhaustion. Cowlib is the HTTP parser used by Cowboy, | RabbitMQ's management plugin, and other Erlang and Elixir HTTP/2 and | HTTP/3 servers and clients, so any exposed endpoint that accepts | HPACK or QPACK from an untrusted peer is reachable. This issue | affects cowlib: from 2.0.0 before 2.19.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59248 https://www.cve.org/CVERecord?id=CVE-2026-59248 [1] https://cna.erlef.org/cves/CVE-2026-59248.html [2] https://github.com/ninenines/cowlib/commit/f582430498072a0c65ad338030321576dc13a343 Regards, Salvatore

