SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65624

MEDIUM · CVSS 6.9 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability in the Cowboy HTTP server allows unauthenticated remote attackers to exploit the HTTP/1.1 handler by sending an unlimited number of header lines with the same name, leading to potential memory exhaustion of the connection process. This can result in out-of-memory conditions for the Erlang VM if the max_heap_size is not configured, making it critical for developers and system administrators using affected versions (2.0.0-pre.4 to 2.18.0) to prioritize remediation. Organizations relying on Cowboy for handling HTTP requests should assess their configurations and apply necessary updates to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65624
Severity
MEDIUM
CVSS
6.9
EPSS
0.38%

Original NVD Description

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in a map (maps:size(Headers)). When a request contains multiple header lines with the same name, the values are concatenated into a single ever-growing binary stored under that one map key (", " for regular headers, "; " for cookies), so the map size stays at one and the max_headers cap (default 100) is never reached. Because no accumulator bounds the total number of header lines or the total byte size of the header block (only per-line max_header_name_length and max_header_value_length apply), an unauthenticated client can send an arbitrary number of header lines with the same name and grow the connection process's binary memory to arbitrary size within the request window. The impact per connection is bounded by request_timeout (default 5 seconds, not reset by header data), and by max_heap_size when set (the offending connection process is killed once its heap grows past the limit). When max_heap_size is left at the default (unset), sustained abuse can drive the Erlang VM into out-of-memory conditions. This issue affects cowboy from 2.0.0-pre.4 before 2.18.0.