CVE-2026-8468 Details
Description
Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the accumulated buffer. By contrast, the sibling function read_part_body has an explicit byte_size(acc) > length guard that stops accumulation once a limit is reached. No such guard exists in read_part_headers. An unauthenticated remote attacker can exhaust server memory by sending a crafted multipart/form-data request, causing a denial of service. This issue affects plug from 1.4.0 before 1.15.4, 1.16.3, 1.17.1, 1.18.2, and 1.19.2.
A denial-of-service vulnerability has been identified in the Plug library, specifically in versions 1.4.0 prior to 1.15.4, as well as 1.16.3, 1.17.1, 1.18.2, and 1.19.2. The issue arises from unbounded buffer accumulation during the parsing of multipart headers. The vulnerability exists in the 'Elixir.Plug.Conn':read_part_headers/2 function, which fails to enforce a limit on the size of the accumulated data. This lack of restriction allows an unauthenticated remote attacker to send multipart/form-data requests that exploit the vulnerability, leading to excessive memory usage and potential exhaustion of server resources.
Users can upgrade to Plug versions 1.15.4, 1.16.3, 1.17.1, 1.18.2, or 1.19.2, all of which contain the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-8466.html | EEF | AdvisoryBundle |
| https://cna.erlef.org/cves/CVE-2026-8468.html | EEF | AdvisoryVendor |
| https://github.com/elixir-plug/plug/commit/2cb7958d33030aa826b0c7404375844d4593d43a | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/33858427c7f2737d560a2e40a0c9a9270d77d1d7 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/aa69c5ece99c40ded88b8c6581ecc86664b0b734 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/d5dfffe25e975585227b1b85d247b0d14164bc45 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/commit/df812a1527bae9e941965e897308a2b8bbf83a94 | EEF | Source CodeVendor |
| https://github.com/elixir-plug/plug/security/advisories/GHSA-468c-vq7p-gh64 | EEF | AdvisoryRemedyVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-8468 | EEF | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | EEF |
Affected Products
| Product | Versions |
|---|---|
| plug_project.plug | >= 1.4.0, < 1.15.4 (semver) >= 1.16.0, < 1.16.3 (semver) >= 1.17.0, < 1.17.1 (semver) >= 1.18.0, < 1.18.2 (semver) >= 1.19.0, < 1.19.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | CVE Modified | EEF |
| May 14, 2026 | New CVE Received | EEF |
Volerion