- Package:
- src:erlang-cowlib
- Source:
- src:erlang-cowlib
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-29 13:09:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for erlang-cowlib. CVE-2026-59248[0]: | Allocation of resources without limits vulnerability in ninenines | cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to | exhaust memory on the vulnerable server (or client) and cause a | denial of service. The HPACK and QPACK prefixed-integer decoder | cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl (invoked | from cow_hpack:decode/2 in src/cow_hpack.erl and from | cow_qpack:decode_field_section/3 in src/cow_qpack.erl) reads | continuation octets until it sees one whose high bit is clear, | evaluating Int + (Value bsl M) at each step with the shift M growing | by seven per octet. No limit is enforced on the number of | continuation octets, on the resulting bit width, or on the value; | the decoder consumes whatever encoded length the peer supplies. | Because Erlang integers are immutable, each intermediate Value bsl M | and each accumulator update allocates a fresh bignum whose digit | width grows linearly with the number of octets processed so far. | Summed across the whole decode, the transient bignum digit | materialization is on the order of the square of the encoded length. | A single maximal HPACK indexed representation carried inside one | HTTP/2 HEADERS plus one CONTINUATION frame at Cowboy's default | max_frame_size_received can force hundreds of megabytes of transient | allocation and garbage-collection churn before the resulting header- | table index is rejected as invalid. Repeated or concurrent | connections multiply the pressure and can drive the Erlang VM to | memory exhaustion. Cowlib is the HTTP parser used by Cowboy, | RabbitMQ's management plugin, and other Erlang and Elixir HTTP/2 and | HTTP/3 servers and clients, so any exposed endpoint that accepts | HPACK or QPACK from an untrusted peer is reachable. This issue | affects cowlib: from 2.0.0 before 2.19.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59248 https://www.cve.org/CVERecord?id=CVE-2026-59248 [1] https://cna.erlef.org/cves/CVE-2026-59248.html [2] https://github.com/ninenines/cowlib/commit/f582430498072a0c65ad338030321576dc13a343 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
erlang-cowlib, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142982@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sergei Golovan <sgolovan@debian.org> (supplier of updated erlang-cowlib package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 29 Jul 2026 15:38:39 +0300
Source: erlang-cowlib
Architecture: source
Version: 2.19.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan@debian.org>
Closes: 1142982
Changes:
erlang-cowlib (2.19.0-1) unstable; urgency=medium
.
* New upstream release.
* Fix CVE-2026-59248: Allocation of resources without limits vulnerability
(closes: #1142982).
Checksums-Sha1:
c80c440aeaa9d15b6420af04774367bb86f5f3cf 2137 erlang-cowlib_2.19.0-1.dsc
c24c080819c4a40c3d8f897b2c736f8cf6ea1244 217375 erlang-cowlib_2.19.0.orig.tar.gz
57b782f3464054c4db05d7c5c4765360f36d7db5 3244 erlang-cowlib_2.19.0-1.debian.tar.xz
036499120949ad211a456e6c88b51dfb0784bf36 6170 erlang-cowlib_2.19.0-1_amd64.buildinfo
Checksums-Sha256:
1a2ae24f5a2cfc37e91255eadf84e4edff74279f5b03af7226509c4116b329e1 2137 erlang-cowlib_2.19.0-1.dsc
10f53ec6833e19f064e54d9da9e9f240100af6d89f62a329e342af2ecf295943 217375 erlang-cowlib_2.19.0.orig.tar.gz
84c0469e09cd8a8ad22bfa8b0e98a77d9df8bc71f5abece2ae4f7e6456602b02 3244 erlang-cowlib_2.19.0-1.debian.tar.xz
23ab56b51a018706ebffe617c72bed87d1f5c61a3dd202bd800d90502251139b 6170 erlang-cowlib_2.19.0-1_amd64.buildinfo
Files:
448ba22489dd627c073ac59bcb97123e 2137 devel optional erlang-cowlib_2.19.0-1.dsc
7709b8f60a1b4acca51b84a3507840ae 217375 devel optional erlang-cowlib_2.19.0.orig.tar.gz
2d2e932e03b361a302e39a1061a70fe1 3244 devel optional erlang-cowlib_2.19.0-1.debian.tar.xz
45235396d7535ca2efd304371ca39926 6170 devel optional erlang-cowlib_2.19.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmpp9MsACgkQTyrk60tj
54dHnBAAjnGrYbiQjGz4+n8Ukfrg2YuDQ0cdw688vAPrORvauEurtUkOO1d917Q5
g3IMSR6SkyaDZqe+qgfkjvKQIc9H1OgjkL2THTMtvtp10cVr4kzfUJHnvgGUbY1z
jtSMFvD9ew8IaD/OfRksRx+Xgz7HgkxJCFIwToNzRgs+Nb8ctfAYKP/4AAhmY8QE
W3rKUUWIFGz0sn1ncvdLEWoHFHZUCUFn5QTIrAAYeIkdBziZVX/xVjGh9fVqki9X
XnyCdsmSGbexZaF2GO2KM2H9NRpK7luIJ7Su/nNvq3y1XSdsH5CbXs0ZC7vc7Zu/
4EqxYaShh3ulr3qaEF2zxhWcW3eoj/iB/PAMhvaCO1JlGC/LpXgrp5IERd1O7N2V
EIEAZEKtrpgvUFaUqbCOQMQRYVMD741tc66kTUc+jJKjErgpRC8qGDLgNNTIHKyQ
Nu6Nw7EnXv2FbLC8oukCxOliVN1/hxp6bl7Ns9fYUve7VemFcZd+uXwZNsYTFqRM
YSmlC1+6Gz6UAHaQ9vlnfqGzUUm9Ju8ByP/VRWTNzBaJufcpc9GwmcjOghkBpkDN
FR2pT1ZKQyNjmnWatJO+CoQqVsjkwkhf3x0yxgEgQgOE9QZsYtvmRQ/w8oUfk4aj
axkg40CsssGW/GBIIypkIahvkIv9q0ZG4/+LKyhdgWNfvhwLr+w=
=jisR
-----END PGP SIGNATURE-----