CVE-2026-7790: Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
Other sources
Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cowhttpte module) allows Excessive Allocation.
The chunked transfer-encoding parser in cowhttpte accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len 16 + digit), so parsing N hex digits requires O(N²) CPU work and O(N) memory. Additionally, when input is drip-fed, the parser discards the accumulated length on each partial read and restarts from zero on resumption, raising the cost to O(N³). An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a very long chunk-size hex string to cause denial of service through CPU exhaustion and memory amplification.
This vulnerability is associated with program file src/cowhttpte.erl and program routines cowhttpte:streamchunked/2, cowhttpte:chunkedlen/4.
This issue affects cowlib: from 0.6.0 before 2.16.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7790?
CVE-2026-7790 has a high severity rating due to its potential for causing denial of service through excessive resource consumption.
How do I fix CVE-2026-7790?
To fix CVE-2026-7790, upgrade to cowlib version 2.16.1 or later, which contains a patch for the vulnerability.
What causes CVE-2026-7790?
CVE-2026-7790 is caused by the chunked transfer-encoding parser in cowlib that accepts an unbounded number of hex digits.
Which versions of cowlib are affected by CVE-2026-7790?
CVE-2026-7790 affects cowlib versions from 0.6.0 to 2.16.1, excluding 2.16.1.
What are the potential impacts of CVE-2026-7790?
The potential impacts of CVE-2026-7790 include increased CPU and memory usage leading to service disruption.