Uncontrolled Resource Consumption in ninenines gun HTTP Module
CVE-2026-43973

8.7HIGH

Key Information:

Vendor

Ninenines

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-43973?

The ninenines gun HTTP module suffers from an uncontrolled resource consumption vulnerability that occurs due to unbounded HTTP response buffering. Attackers can exploit this issue by sending partial HTTP responses that lack the necessary terminators, leading to excessive cumulative memory usage as the server continues to append incoming data without a limit. The vulnerability affects versions of gun from 1.0.0 to just before 2.4.0, posing a significant risk of out-of-memory crashes that can impact the entire server node.

Affected Version(s)

gun 1.0.0 < 2.4.0

gun 11dfe71f4b9aedaaedea2ad3b2f32fd006a8480f

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Loïc Hoguin
.