plug_cowboy
A Plug adapter for Cowboy
Activity
- Latest release
- 2mo ago
- Total releases
- 29
- Cadence
- ~3 months
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Oct 20, 2018
| Version | Released | |
|---|---|---|
2.9.0
minor
| ||
2.8.1
patch
| ||
2.8.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.5
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.4
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.3
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.6.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.6.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.5.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.5.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.4.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.1.3
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-32688
GHSA-q8x4-x7mp-5vg2
EEF-CVE-2026-32688
May 05, 2026
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion
High
Network
Low
None
None
SummaryAn unauthenticated remote denial-of-service vulnerability in Am I Affected?All users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected. ImpactThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion. MitigationUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue. CreditsPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability. Affected versions
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
+ 14 more Show less
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0
Fixed in
2.8.1
References
Updated May 05, 2026 · Source: OSV.dev | ||
1.0.0
initial
|