VYPR

gun_http

by Ninenines

CVEs (1)

  • CVE-2026-43973HigJun 8, 2026
    risk 0.50cvss epss

    Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP data into the connection's buffer field…