{"id":"GHSA-84f2-rp86-235p","summary":"cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","details":"Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion.\n\ncow_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes directly to zlib:inflate/2 with no output size bound. The SPDY header compression dictionary (?ZDICT) is public, and zlib compresses long runs of repeated bytes at roughly 1024:1, so a few kilobytes of SPDY frame payload can decompress to gigabytes on the BEAM heap, OOM-killing the node. A single unauthenticated SPDY frame is sufficient to trigger the condition. The parsers for syn_stream, syn_reply, and headers frame types are all affected via cow_spdy:parse_headers/2.\n\nThis issue affects cowlib from 0.1.0 before 2.16.1.","aliases":["CVE-2026-43970","EEF-CVE-2026-43970"],"modified":"2026-05-19T20:26:01.036608498Z","published":"2026-05-13T21:32:06Z","database_specific":{"cwe_ids":["CWE-409"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-19T20:12:01Z","nvd_published_at":"2026-05-13T19:17:25Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43970"},{"type":"WEB","url":"https://github.com/ninenines/cowlib/commit/16aad3fb9f81f5cda4d1706ff0c54237c619c282"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-43970.html"},{"type":"PACKAGE","url":"https://github.com/ninenines/cowlib"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-43970"}],"affected":[{"package":{"name":"cowlib","ecosystem":"Hex","purl":"pkg:hex/cowlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"fixed":"2.16.1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-84f2-rp86-235p/GHSA-84f2-rp86-235p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}