CVE-2026-43973
- EPSS 0.48%
- Veröffentlicht 08.06.2026 14:12:42
- Zuletzt bearbeitet 18.08.2026 15:43:43
Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP data into th...
CVE-2026-43972
- EPSS 0.17%
- Veröffentlicht 08.06.2026 14:12:38
- Zuletzt bearbeitet 18.08.2026 15:42:54
Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidated HTTP/2 PUSH_PROMISE authority. In gun_http2:push_promise_frame/7, the :authority pseudo-header from an incoming PUSH_PROMI...
CVE-2026-43974
- EPSS 0.48%
- Veröffentlicht 08.06.2026 14:12:36
- Zuletzt bearbeitet 18.08.2026 15:44:36
Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when ...