Resource Exhaustion Vulnerability in ninenines Cowboy HTTP Server
CVE-2026-65624
What is CVE-2026-65624?
An unbounded allocation of resources vulnerability exists in the ninenines Cowboy HTTP server that allows unauthenticated remote attackers to exhaust the connection process's memory. This is caused by improper handling of HTTP headers, enabling attackers to send numerous headers with the same name, resulting in unrestrained growth of the connection's binary memory. The request timeout and max heap size parameters set limits, but leaving defaults can lead to server instability and potential out-of-memory erros. This vulnerability impacts Cowboy versions between 2.0.0-pre.4 and 2.18.0.
Affected Version(s)
cowboy 2.0.0-pre.4 < 2.18.0
cowboy 309780a9fda145c262a47ac7811ffd50a0271c5b < 3a34d8c1cfd94326466aa16a9017236691dc9c55
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
