Skip to content
Fedora 43 erlang-cowboy Denial Service Fix Advisory 2026

Fedora 43 erlang-cowboy Denial Service Fix Advisory 2026

Linuxsecurity •LinuxSecurity Advisories • August 14, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

Small, fast, modular HTTP server written in Erlang.

Coordinated security update of cowlib and cowboy, released together upstream on 2026-07-27. cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION frames and NUL bytes in multipart headers, validates cookie domain and path, limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket- Version limits to response headers, and enforces a custom max_concurrent_streams immediately. cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR in HTTP/1.1 header values, rejects requests containing a fragment component, rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies option to the cowboy_req cookie functions, fixes max_headers handling with duplicate headers, and fixes the websocket max_inflate_size calculation. Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1 requests. Applications...

* Wed Aug 5 2026 Peter Lemenkov - 2.18.0-1 - Cowboy ver. 2.18.0 * Wed Jul 15 2026 Fedora Release Engineering - 2.17.0-2 - Rebuilt for

* Wed Aug 5 2026 Peter Lemenkov - 2.18.0-1 - Cowboy ver. 2.18.0 * Wed Jul 15 2026 Fedora Release Engineering - 2.17.0-2 - Rebuilt for

[ 1 ] Bug #2508040 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-44] [ 2 ] Bug #2508041 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-43]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ce97d80dae' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Attack Types (1)

Platforms (1)