Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed

Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed

First seen 21 Jun 2026, 02:19 UTC Linuxsecurity 90% similarity 72.9

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities have been identified in Fedora's Erlang packages, specifically affecting erlang-gun and erlang-cowboy. CVE-2026-43972 involves a cross-origin cookie injection leading to session fixation and account takeover, while CVE-2026-43974 and CVE-2026-43973 address Denial of Service (DoS) vulnerabilities. The vulnerabilities were published on June 8, 2026, and impact Fedora 43 and 44 users. Users are urged to update their systems immediately to mitigate these risks. The updates can be installed using the 'dnf' update program. The vulnerabilities were reported by Peter Lemenkov, a Fedora maintainer. The affected versions include erlang-gun 2.4.0 and 2.4.1, and erlang-cowboy 2.16.0 and 2.16.1. Current advisories emphasize the urgency of applying the patches.

Key Points: • Critical vulnerabilities in Fedora's Erlang packages affect multiple versions. • CVE-2026-43972 allows for session fixation and account takeover. • Immediate updates are necessary to mitigate Denial of Service risks.

ThreatCluster AI How this analysis works

Timeline

2026-06-08
CVE-2026-43972 published
Cross-origin cookie injection vulnerability in erlang-gun leading to session fixation and account takeover.
Article 3
2026-06-08
CVE-2026-43973 published
Denial of Service vulnerability in erlang-gun due to unbounded HTTP/1.1 response buffering.
Article 5
2026-06-08
CVE-2026-43974 published
Denial of Service vulnerability in erlang-gun via unsolicited 101 Switching Protocols response.
Article 4
2026-06-21
Critical advisories released
Fedora users are urged to update their systems to address the critical vulnerabilities in Erlang packages.
Article 1

Community

Browse all →

Tracked Entities in This Story