Linuxsecurity Denial of Service Vulnerability in Fedora's erlang-cowboy and cowlib
Article Content
- •CVE-2026-59248 affects Fedora 43 and 44 due to a denial of service vulnerability.
- •The vulnerability is linked to unbounded HPACK/QPACK decoding in erlang-cowboy and cowlib.
- •Users are urged to apply the security updates released on 2026-07-27 immediately.
A coordinated security update was released for Fedora 43 and 44 addressing CVE-2026-59248, a denial of service vulnerability in the erlang-cowboy and cowlib libraries. This vulnerability stems from unbounded HPACK/QPACK prefixed-integer decoding, which could lead to service disruption. The updates were released upstream on 2026-07-27, with affected versions being cowlib 2.19.0 and cowboy 2.18.0. Key fixes include rejecting empty HTTP/2 CONTINUATION frames and limiting cookie parsing. Users are advised to upgrade their systems using the dnf update program. The vulnerability was published on 2026-07-28, and both Fedora 43 and 44 are impacted. The updates are crucial for maintaining system integrity and availability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Fedora and CVE-2026-59248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…