Resource Exhaustion Vulnerability in ninenines Cowboy HTTP Server
CVE-2026-65624

6.9MEDIUM

Key Information:

Vendor

Ninenines

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-65624?

An unbounded allocation of resources vulnerability exists in the ninenines Cowboy HTTP server that allows unauthenticated remote attackers to exhaust the connection process's memory. This is caused by improper handling of HTTP headers, enabling attackers to send numerous headers with the same name, resulting in unrestrained growth of the connection's binary memory. The request timeout and max heap size parameters set limits, but leaving defaults can lead to server instability and potential out-of-memory erros. This vulnerability impacts Cowboy versions between 2.0.0-pre.4 and 2.18.0.

Affected Version(s)

cowboy 2.0.0-pre.4 < 2.18.0

cowboy 309780a9fda145c262a47ac7811ffd50a0271c5b < 3a34d8c1cfd94326466aa16a9017236691dc9c55

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qiyi Deng / Wuhan University
Min Shi / Wuhan University
Yongkang Xiao / Wuhan University
Jing Chen / Wuhan University
LoĂŻc Hoguin
Jonatan Männchen / EEF
.