PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7790 ninenines CVE debrief

CVE-2026-7790 is a denial-of-service issue in cowlib’s HTTP chunked transfer-encoding parser. The parser accepts an unbounded number of hex digits in the chunk-size field, which can force excessive CPU work and memory use while parsing. According to the advisory, a drip-fed request can make the cost even worse by causing the parser to restart its accumulated length on each partial read. This is a remotely reachable, unauthenticated resource-consumption problem affecting cowlib from 0.6.0 before 2.16.1.

Vendor
ninenines
Product
cowlib
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-11
Original CVE updated
2026-05-13
Advisory published
2026-05-11
Advisory updated
2026-05-13

Who should care

Operators and maintainers of Erlang/Elixir services that depend on cowlib, especially HTTP-facing systems that accept HTTP/1.1 chunked requests through internet-exposed endpoints or reverse-proxy paths.

Technical summary

The issue is in cow_http_te’s chunked transfer-encoding parsing routines. The chunk-size parser accepts an unbounded hex string, so each digit expands a big integer-style length calculation. The advisory states this yields O(N^2) CPU work and O(N) memory for a long chunk-size field, and that drip-fed input can raise the total cost to O(N^3) because partial reads discard accumulated length and restart parsing from zero. The vulnerability is mapped to CWE-400 (Uncontrolled Resource Consumption).

Defensive priority

High

Recommended defensive actions

  • Upgrade cowlib to 2.16.1 or later.
  • Identify all applications and transitive dependencies that embed cowlib, including services that parse HTTP chunked transfer-encoding.
  • Add or tighten request size, header size, and connection-timeout limits at the edge or reverse proxy.
  • Monitor for CPU spikes, worker exhaustion, or repeated chunked-request parsing on exposed HTTP endpoints.
  • Review dependency lockfiles and build artifacts to confirm no affected cowlib version from 0.6.0 before 2.16.1 remains deployed.

Evidence notes

The supplied sources identify the issue as an uncontrolled resource consumption vulnerability in ninenines cowlib’s cow_http_te module, affecting versions from 0.6.0 before 2.16.1. The NVD record cites CWE-400 and marks the record as Undergoing Analysis. References in the corpus include the CNA advisory at cna.erlef.org, an upstream GitHub commit in the ninenines/cowlib repository, and an OSV entry for EEF-CVE-2026-7790. The source description states the attack is possible remotely and without authentication via HTTP/1.1 chunked transfer-encoding with an oversized chunk-size hex string.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-7790 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-7790

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-7790 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7790

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-7790.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-7790

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.