cowboy
Hex3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cowboypage 1 of 1
- CVE-2026-43966MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.16.02026-06-08
vulnerable: 1.0.0 ... 2.9.0 (31 versions)
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values. cow_http_struct_hd:esca…
- CVE-2026-65624MEDIUMCVSS 6.9EG 6.9✓ Fixed in 2.18.02026-07-28
vulnerable: 2.0.0 ... 2.9.0 (26 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_head…
- CVE-2026-8466HIGHCVSS 8.2EG 8.2✓ Fixed in 2.15.02026-05-13
vulnerable: 2.0.0 ... 2.9.0 (22 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incomi…
Check whether cowboy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cowboy CVEs against the assets you own.
Start Free Scan →