CVE-2026-7790 Details
Description
Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len * 16 + digit), so parsing N hex digits requires O(N²) CPU work and O(N) memory. Additionally, when input is drip-fed, the parser discards the accumulated length on each partial read and restarts from zero on resumption, raising the cost to O(N³). An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a very long chunk-size hex string to cause denial of service through CPU exhaustion and memory amplification. This vulnerability is associated with program file src/cow_http_te.erl and program routines cow_http_te:stream_chunked/2, cow_http_te:chunked_len/4. This issue affects cowlib: from 0.6.0 before 2.16.1.
A denial-of-service vulnerability has been identified in ninenines cowlib, specifically within the cow_http_te module. This vulnerability arises from the chunked transfer-encoding parser, which accepts an unbounded number of hex digits in the chunk-size field. Each digit triggers a bignum multiplication, leading to quadratic CPU consumption and linear memory usage. When the input is drip-fed, the parser resets the accumulated length after each partial read, causing the resource consumption to escalate to cubic complexity. An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a lengthy chunk-size hex string, resulting in CPU exhaustion and memory amplification. This issue affects cowlib versions 0.6.0 prior to 2.16.1.
Users can update to cowlib version 2.16.1 or later, where this vulnerability has been fixed. For applications using Cowboy, lowering the initial_stream_flow_size can help mitigate the vulnerability's impact by reducing the amount of chunked data parsed in a single read.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-7790.html | EEF | Third Party Advisory |
| https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369 | EEF | Patch |
| https://osv.dev/vulnerability/EEF-CVE-2026-7790 | EEF | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | EEF |
Affected Products
| Product | Versions |
|---|---|
| ninenines cowlib | >= 0.6.0, < 2.16.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | New CVE Received | EEF |