Source: erlang-cowboy
Version: 2.17.0+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for erlang-cowboy.

CVE-2026-65624[0]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in ninenines cowboy allows an unauthenticated remote attacker to
| exhaust connection process memory over HTTP/1.1.  The HTTP/1.1
| handler in cowboy_http enforces the max_headers limit by counting
| the number of distinct header names in a map (maps:size(Headers)).
| When a request contains multiple header lines with the same name,
| the values are concatenated into a single ever-growing binary stored
| under that one map key (", " for regular headers, "; " for cookies),
| so the map size stays at one and the max_headers cap (default 100)
| is never reached. Because no accumulator bounds the total number of
| header lines or the total byte size of the header block (only per-
| line max_header_name_length and max_header_value_length apply), an
| unauthenticated client can send an arbitrary number of header lines
| with the same name and grow the connection process's binary memory
| to arbitrary size within the request window.  The impact per
| connection is bounded by request_timeout (default 5 seconds, not
| reset by header data), and by max_heap_size when set (the offending
| connection process is killed once its heap grows past the limit).
| When max_heap_size is left at the default (unset), sustained abuse
| can drive the Erlang VM into out-of-memory conditions.  This issue
| affects cowboy from 2.0.0-pre.4 before 2.18.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65624
    https://www.cve.org/CVERecord?id=CVE-2026-65624
[1] https://cna.erlef.org/cves/CVE-2026-65624.html
[2] https://osv.dev/vulnerability/EEF-CVE-2026-65624
[3] 
https://github.com/ninenines/cowboy/commit/3a34d8c1cfd94326466aa16a9017236691dc9c55

Regards,
Salvatore

Reply via email to