Skip to content
Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed

Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed

First seen 21 Jun 2026, 02:19 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 22, 2026 at 00:04 UTC
  • Critical vulnerabilities in Fedora's Erlang packages affect multiple versions.
  • CVE-2026-43972 allows for session fixation and account takeover.
  • Immediate updates are necessary to mitigate Denial of Service risks.

Multiple critical vulnerabilities have been identified in Fedora's Erlang packages, specifically affecting erlang-gun and erlang-cowboy. CVE-2026-43972 involves a cross-origin cookie injection leading to session fixation and account takeover, while CVE-2026-43974 and CVE-2026-43973 address Denial of Service (DoS) vulnerabilities. The vulnerabilities were published on June 8, 2026, and impact Fedora 43 and 44 users. Users are urged to update their systems immediately to mitigate these risks. The updates can be installed using the 'dnf' update program. The vulnerabilities were reported by Peter Lemenkov, a Fedora maintainer. The affected versions include erlang-gun 2.4.0 and 2.4.1, and erlang-cowboy 2.16.0 and 2.16.1. Current advisories emphasize the urgency of applying the patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-06-08
CVE-2026-43972 published
Cross-origin cookie injection vulnerability in erlang-gun leading to session fixation and account takeover.
Article 3
2026-06-08
CVE-2026-43973 published
Denial of Service vulnerability in erlang-gun due to unbounded HTTP/1.1 response buffering.
Article 5
2026-06-08
CVE-2026-43974 published
Denial of Service vulnerability in erlang-gun via unsolicited 101 Switching Protocols response.
Article 4
2026-06-21
Critical advisories released
Fedora users are urged to update their systems to address the critical vulnerabilities in Erlang packages.
Article 1

More articles in this cluster (6)

Following this threat?

Track Fedora and CVE-2026-43972 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed