{"id":"GHSA-q8x4-x7mp-5vg2","summary":"Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion","details":"## Summary\n\nAn unauthenticated remote denial-of-service vulnerability in `Plug.Cowboy.Conn` allows any attacker who can reach an HTTPS Plug.Cowboy listener via HTTP/2 to permanently exhaust the BEAM atom table and crash the entire Erlang VM.\n\n## Am I Affected?\n\nAll users running plug_cowboy with HTTP/2 may be affected, this includes Phoenix applications. If another HTTP adapter such as Bandit is used, then the consuming project is not affected. If the HTTP/2 endpoint is exposed directly (without a proxy) then the project will be affected. If a proxy is in use then it depends on the proxy configuration. Many proxies use HTTP/1.1 internally, and would be unaffected.\n\n## Impact\n\nThe vulnerability will allow crashing the Erlang VM (BEAM) via atom exhaustion.\n\n## Mitigation\n\nUsers are advised to update to plug_cowboy v2.8.1 to mitigate this issue.\n\n## Credits\nPlug.Cowboy thanks Peter Ullrich for finding and responsibly disclosing this vulnerability.","aliases":["CVE-2026-32688","EEF-CVE-2026-32688"],"modified":"2026-05-05T22:05:44.180186Z","published":"2026-05-05T21:46:09Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-05T21:46:09Z","nvd_published_at":"2026-04-27T14:16:47Z","cwe_ids":["CWE-770"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/elixir-plug/plug_cowboy/security/advisories/GHSA-q8x4-x7mp-5vg2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32688"},{"type":"WEB","url":"https://github.com/elixir-plug/plug_cowboy/commit/bfb34cb45eb354e56437f7023fb306de1bf9c19b"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-32688.html"},{"type":"PACKAGE","url":"https://github.com/elixir-plug/plug_cowboy"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-32688"}],"affected":[{"package":{"name":"plug_cowboy","ecosystem":"Hex","purl":"pkg:hex/plug_cowboy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.8.1"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.2.2","2.3.0","2.4.0","2.4.1","2.5.0","2.5.1","2.5.2","2.6.0","2.6.1","2.6.2","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q8x4-x7mp-5vg2/GHSA-q8x4-x7mp-5vg2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}