#1142988 erlang-cowboy: CVE-2026-65624

Package:
src:erlang-cowboy
Source:
src:erlang-cowboy
Submitter:
Salvatore Bonaccorso
Date:
2026-07-29 13:41:03 UTC
Severity:
normal
Tags:
#1142988#5
Date:
2026-07-29 12:24:30 UTC
From:
To:
Hi,

The following vulnerability was published for erlang-cowboy.

CVE-2026-65624[0]:
| Allocation of Resources Without Limits or Throttling vulnerability
| in ninenines cowboy allows an unauthenticated remote attacker to
| exhaust connection process memory over HTTP/1.1.  The HTTP/1.1
| handler in cowboy_http enforces the max_headers limit by counting
| the number of distinct header names in a map (maps:size(Headers)).
| When a request contains multiple header lines with the same name,
| the values are concatenated into a single ever-growing binary stored
| under that one map key (", " for regular headers, "; " for cookies),
| so the map size stays at one and the max_headers cap (default 100)
| is never reached. Because no accumulator bounds the total number of
| header lines or the total byte size of the header block (only per-
| line max_header_name_length and max_header_value_length apply), an
| unauthenticated client can send an arbitrary number of header lines
| with the same name and grow the connection process's binary memory
| to arbitrary size within the request window.  The impact per
| connection is bounded by request_timeout (default 5 seconds, not
| reset by header data), and by max_heap_size when set (the offending
| connection process is killed once its heap grows past the limit).
| When max_heap_size is left at the default (unset), sustained abuse
| can drive the Erlang VM into out-of-memory conditions.  This issue
| affects cowboy from 2.0.0-pre.4 before 2.18.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65624
https://www.cve.org/CVERecord?id=CVE-2026-65624
[1] https://cna.erlef.org/cves/CVE-2026-65624.html
[2] https://osv.dev/vulnerability/EEF-CVE-2026-65624
[3] https://github.com/ninenines/cowboy/commit/3a34d8c1cfd94326466aa16a9017236691dc9c55

Regards,
Salvatore

#1142988#10
Date:
2026-07-29 13:39:02 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
erlang-cowboy, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142988@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sergei Golovan <sgolovan@debian.org> (supplier of updated erlang-cowboy package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 29 Jul 2026 15:42:55 +0300
Source: erlang-cowboy
Architecture: source
Version: 2.18.0+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan@debian.org>
Closes: 1142988
Changes:
 erlang-cowboy (2.18.0+dfsg-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
   * Fix CVE-2026-65624: Allocation of Resources Without Limits or
     Throttling vulnerability (closes: #1142988).
Checksums-Sha1:
 916dbd6a2e67945136f5299b9afbd66217c1beaa 2317 erlang-cowboy_2.18.0+dfsg-1.dsc
 df53bba4c58835cf56a12b93531ecf9623bc42f5 2049016 erlang-cowboy_2.18.0+dfsg.orig.tar.xz
 a439a83e0efa758e21a13146dbf79be21b7932ca 4080 erlang-cowboy_2.18.0+dfsg-1.debian.tar.xz
 5b1a0648366cc06d41c77997103ed2d4c89a7a94 11010 erlang-cowboy_2.18.0+dfsg-1_amd64.buildinfo
Checksums-Sha256:
 2c515b5d2da371d60c6dd1e17fa19fe9e0f9ff8695fc7912732a114ac582bdff 2317 erlang-cowboy_2.18.0+dfsg-1.dsc
 0be49d8e841e2b84686b3cd77f2df1d4d78690404769f411a7d0039ce98ff16a 2049016 erlang-cowboy_2.18.0+dfsg.orig.tar.xz
 156ae90f673231a69bb8c838627ddfb07cea8c2bd5514606d8883514ea28c1cf 4080 erlang-cowboy_2.18.0+dfsg-1.debian.tar.xz
 525e2ea601bdfb1ac5bd435fcd020c675f32924e6dacf5edd2db6deed981ceff 11010 erlang-cowboy_2.18.0+dfsg-1_amd64.buildinfo
Files:
 e7b1527e3571e548d15d593e0603d64a 2317 devel optional erlang-cowboy_2.18.0+dfsg-1.dsc
 8d587ac96619193baf3aeeb42c8178bc 2049016 devel optional erlang-cowboy_2.18.0+dfsg.orig.tar.xz
 c47b48ef171760075de24f381e89b8e4 4080 devel optional erlang-cowboy_2.18.0+dfsg-1.debian.tar.xz
 ff1052f440c127e00e0b5b36c999f6a4 11010 devel optional erlang-cowboy_2.18.0+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmpp/X8ACgkQTyrk60tj
54eNxxAA0hEwT6bJDdLqMzl5ornCl+pC5GsRqGrOg5YyjGi36IyA93meT4iUVIz1
zDvQ22/KbUqoZGGJAKMoppCYNa/YxZMSyzKH+S8YfYLj7WGAnbcn5VbtczCXfjXA
iaUa9Wh0otXmgEyI4FOc7Fb7+XPtkPY0S0CGKf1aTnQAFtm9x6WySy2btsjOv9Ft
/HJxXjH2Ijb9lcDN9FKS8wVKkY0EoGtLn/7V3kmaoRtSzb3AGalj2VRwWdo+zDnd
skc7KN8RaqqxYHuMBOhX9h/ckOt/5721+FGZmSxMglnA+8sAfkUM2FwtqcszbjgL
lsR3VRC+ws2w6Y0klYEVOz2YX6Qo2sNey26C/5fFQbcLe8MOT11qGsQil0cJrF9R
oV+RoiK9qkxP17lkJf3ixvkozA0uF2HDOJe8zxKZAtqpb2a36YXBduHLDemkJS+k
MRmwoD6qt8WPSR0f3XdBNThGUw8cD/s2I8vBVw83L8Vg3jZD3cnzLkZ6QAcX9Gfq
8OoSUN6CpJ5KIMeddO9PKNYWBEjw8CqPeFlv3jOrdMOdMtgPAXce37hWkrBaR1eJ
QzYln0tR6r7FTddWZAwiX9njmdyy6fi0wHa5G1T4kuPLv6asB9IKNngGfwc3h8mp
kL6nTjurU9qZww2gSmLQAz75niT5MFeypqLRYXrpqOFeJvF53z0=
=pdc2
-----END PGP SIGNATURE-----