Denial of Service Vulnerability in Fedora's erlang-cowboy and cowlib

Denial of Service Vulnerability in Fedora's erlang-cowboy and cowlib

First seen 14 Aug 2026, 10:46 UTC Linuxsecurity 99% similarity 57.9

Article Content

Browse articles
ThreatCluster

A coordinated security update was released for Fedora 43 and 44 addressing CVE-2026-59248, a denial of service vulnerability in the erlang-cowboy and cowlib libraries. This vulnerability stems from unbounded HPACK/QPACK prefixed-integer decoding, which could lead to service disruption. The updates were released upstream on 2026-07-27, with affected versions being cowlib 2.19.0 and cowboy 2.18.0. Key fixes include rejecting empty HTTP/2 CONTINUATION frames and limiting cookie parsing. Users are advised to upgrade their systems using the dnf update program. The vulnerability was published on 2026-07-28, and both Fedora 43 and 44 are impacted. The updates are crucial for maintaining system integrity and availability.

Key Points: • CVE-2026-59248 affects Fedora 43 and 44 due to a denial of service vulnerability. • The vulnerability is linked to unbounded HPACK/QPACK decoding in erlang-cowboy and cowlib. • Users are urged to apply the security updates released on 2026-07-27 immediately.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Coordinated security update released
Fedora released updates for cowlib 2.19.0 and cowboy 2.18.0 to address CVE-2026-59248.
Article 1
2026-07-28
CVE-2026-59248 published
The vulnerability was officially published, highlighting the risk of denial of service due to unbounded decoding.
Article 1
2026-08-14
Advisories published for Fedora 43 and 44
Linuxsecurity published advisories detailing the denial of service vulnerability and urging updates.
Article 1

Community

Browse all →

Tracked Entities in This Story