CVE-2026-54892 Details
Description
Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn.Query.decode_each/2) parse query strings and application/x-www-form-urlencoded request bodies. When a key contains many bracketed segments such as a[a][a][a]=1, the decoder walks the brackets and, for each of the N levels, performs a map operation keyed on an ever-growing binary prefix of the key, hashing the full byte range at each step. The total decode cost is therefore quadratic in the number of nesting levels. With the default Plug.Parsers.URLENCODED body limit of 1,000,000 bytes, a single request can carry roughly 333,000 nesting levels and saturate a BEAM scheduler for minutes. A small number of concurrent requests can saturate all schedulers and render a Plug-based server unresponsive. No authentication or knowledge of application routes is required. This vulnerability is associated with program files lib/plug/conn/query.ex and program routines Plug.Conn.Query.decode/4, Plug.Conn.Query.decode_each/2, Plug.Conn.Query.split_keys/6, Plug.Conn.Query.insert_keys/3, and Plug.Conn.Query.finalize_pointer/2. This issue affects plug from 1.15.0 before 1.15.5, 1.16.4, 1.17.2, 1.18.3, and 1.19.3.
A denial-of-service vulnerability has been identified in the Plug library, specifically in versions 1.15.0 prior to 1.15.5, 1.16.0 prior to 1.16.4, 1.17.0 prior to 1.17.2, 1.18.0 prior to 1.18.3, and 1.19.0 prior to 1.19.3. The issue arises from an inefficient algorithmic complexity in Plug's nested-parameter decoder, which is used to parse query strings and application/x-www-form-urlencoded request bodies. When a key contains multiple bracketed segments, the decoder's processing time increases quadratically with the number of nesting levels. This vulnerability allows an unauthenticated remote attacker to send a request that can block a BEAM scheduler for several minutes, potentially rendering a Plug-based server unresponsive. The vulnerability does not require any authentication or knowledge of application routes, and can be exploited by sending specially crafted query parameters that exploit the decoding algorithm's complexity.
Users can upgrade to Plug versions 1.15.5, 1.16.4, 1.17.2, 1.18.3, or 1.19.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/elixir-plug/plug/security/advisories/GHSA-j43x-5hjq-rgxf | CISA-ADP | AdvisoryVendor |
| https://cna.erlef.org/cves/CVE-2026-54892.html | EEF | AdvisoryVendor |
| https://github.com/elixir-plug/plug/commit/9c5d37c440eaae92869eed7c014c47266744fadb | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/a61124aa625d819a218fb07f90afbac8aa85eb0e | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/c317d08fdcf96e17931f7419275b2b8c4bf3e951 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/d4e5568392a4b29e545b91e12e87d6098f976145 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/d737eb236f17e31a36290e39f9ef3cd86a1343bd | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/security/advisories/GHSA-j43x-5hjq-rgxf | EEF | AdvisoryVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-54892 | EEF | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-407 | Inefficient Algorithmic Complexity | EEF |
Affected Products
| Product | Versions |
|---|---|
| Plug | >= 1.15.0, < 1.15.5 (semver) >= 1.16.0, < 1.16.4 (semver) >= 1.17.0, < 1.17.2 (semver) >= 1.18.0, < 1.18.3 (semver) >= 1.19.0, < 1.19.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | EEF |
Volerion