216.73.217.22

CVE-2026-8468

· Published 14/05/2026 11:16 · Modified 14/05/2026 17:07

Labels: CVE-2026-8468 2026-05-146b3ad84c-e1a6-4bf7-a703-f496b71e49dbCVE-2026-8468CWE-770

Essential information

Published
14/05/2026 11:16
Modified
14/05/2026 17:07
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the accumulated buffer. By contrast, the sibling function read_part_body has an explicit byte_size(acc) > length guard that stops accumulation once a limit is reached. No such guard exists in read_part_headers. An unauthenticated remote attacker can exhaust server memory by sending a crafted multipart/form-data request, causing a denial of service. This issue affects plug from 1.4.0 before 1.15.4, 1.16.3, 1.17.1, 1.18.2, and 1.19.2.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
NVD
View on NVD

Affected products (CPE)

ProductCPE
elixir / plug cpe:2.3:a:elixir:plug:1.4.0-1.15.4:*:*:*:*:*:*:*
elixir / plug cpe:2.3:a:elixir:plug:1.16.3:*:*:*:*:*:*:*
elixir / plug cpe:2.3:a:elixir:plug:1.17.1:*:*:*:*:*:*:*
elixir / plug cpe:2.3:a:elixir:plug:1.18.2:*:*:*:*:*:*:*
elixir / plug cpe:2.3:a:elixir:plug:1.19.2:*:*:*:*:*:*:*

References