{"id":"GHSA-32p9-57cr-4x65","summary":" cowlib cow_http_te module: Uncontrolled Resource Consumption vulnerability allows Excessive Allocation","details":"Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation.\n\nThe chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len * 16 + digit), so parsing N hex digits requires O(N²) CPU work and O(N) memory. Additionally, when input is drip-fed, the parser discards the accumulated length on each partial read and restarts from zero on resumption, raising the cost to O(N³). An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a very long chunk-size hex string to cause denial of service through CPU exhaustion and memory amplification.\n\nThis vulnerability is associated with program file src/cow_http_te.erl and program routines cow_http_te:stream_chunked/2, cow_http_te:chunked_len/4.\n\nThis issue affects cowlib: from 0.6.0 before 2.16.1.","aliases":["CVE-2026-7790","EEF-CVE-2026-7790"],"modified":"2026-05-18T17:11:03.404309115Z","published":"2026-05-11T21:31:35Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-18T16:49:21Z","nvd_published_at":"2026-05-11T19:16:29Z","cwe_ids":["CWE-400"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7790"},{"type":"WEB","url":"https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-7790.html"},{"type":"PACKAGE","url":"https://github.com/ninenines/cowlib"},{"type":"WEB","url":"https://github.com/ninenines/cowlib/releases/tag/2.16.1"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-7790"}],"affected":[{"package":{"name":"cowlib","ecosystem":"Hex","purl":"pkg:hex/cowlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.0"},{"fixed":"2.16.1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-32p9-57cr-4x65/GHSA-32p9-57cr-4x65.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}