{"id":"AZL-88266","summary":"CVE-2026-8466 affecting package rabbitmq-server for versions less than 3.13.7-5","details":"Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing.\n\ncowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When cow_multipart:parse_headers/2 returns more or {more, Buffer2}, the function reads up to Length bytes (default 64 KB) from the request body and recurses with the enlarged buffer. There is no equivalent of the byte_size(Acc) \u003e Length guard present in the sibling function read_part_body/4. An unauthenticated attacker can send a multipart/form-data request whose body never yields a complete header section — for example, a body that never contains the advertised boundary delimiter, or one whose header lines never contain \\r\\n\\r\\n — and force the server process to accumulate memory linearly with the bytes the protocol layer is willing to deliver. A handful of concurrent such uploads is sufficient to exhaust BEAM memory.\n\nThis issue affects cowboy from 2.0.0 before 2.15.0.","modified":"2026-09-02T06:51:55Z","published":"2026-05-13T19:17:30Z","upstream":["CVE-2026-8466"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8466"}],"affected":[{"package":{"name":"rabbitmq-server","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rabbitmq-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.7-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88266.json"}}],"schema_version":"1.9.0"}