CVE-2026-8466
Last modified
CVE-2026-8466 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When cow_multipart:parse_headers/2 returns more or {more, Buffer2}, the function reads up to Length bytes (default 64 KB) from the request body and recurses with the enlarged buffer. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When cow_multipart:parse_headers/2 returns more or {more, Buffer2}, the function reads up to Length bytes (default 64 KB) from the request body and recurses with the enlarged buffer. There is no equivalent of the byte_size(Acc) > Length guard present in the sibling function read_part_body/4. An unauthenticated attacker can send a multipart/form-data request whose body never yields a complete header section — for example, a body that never contains the advertised boundary delimiter, or one whose header lines never contain \r\n\r\n — and force the server process to accumulate memory linearly with the bytes the protocol layer is willing to deliver. A handful of concurrent such uploads is sufficient to exhaust BEAM memory. This issue affects cowboy from 2.0.0 before 2.15.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8466?
How severe is CVE-2026-8466?
How do I fix CVE-2026-8466?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84654In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093…5.4
- CVE-2026-84655Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not …4.3
- CVE-2026-84656A missing permission check in Jenkins 2.579 and earlier, LTS…4.3
- CVE-2026-84657In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the b…4.2
- CVE-2026-84658Jenkins Script Security Plugin 1412.v7737b_3405f86 and earli…4.3
- CVE-2026-84659Jenkins Script Security Plugin 1412.v7737b_3405f86 and earli…4.3
- CVE-2026-84660A missing permission check in Jenkins Pipeline: Build Step P…5.4
- CVE-2026-84661A missing permission check in Jenkins Pipeline: Build Step P…5.4
- CVE-2026-84662Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allow…4.3
- CVE-2026-84663A cross-site request forgery (CSRF) vulnerability in Jenkins…5.4
- CVE-2026-84664Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting …5.4
- CVE-2026-84665Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not…8
Are you affected by CVE-2026-8466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
