VYPR

Cowboy

by Ninenines

Source repositories

CVEs (2)

  • CVE-2026-8466HigMay 13, 2026
    risk 0.46cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary…

  • CVE-2026-65624MedJul 28, 2026
    risk 0.38cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of…