CVE-2026-32688Disclosure(elixir-plug / plug.cowboy)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustion. Plug.Cowboy.Conn.conn/1 in lib/plug/cowboy/conn.ex calls String.to_atom/1 on the value returned by :cowboy_req.scheme/1. For HTTP/2 connections, cowlib passes the client-supplied :scheme pseudo-header value through verbatim without validation. Each unique value permanently allocates a new entry in the BEAM atom table. Since atoms are never garbage-collected and the atom table has a fixed limit (default 1,048,576), an unauthenticated attacker can exhaust the table by sending HTTP/2 requests with unique :scheme values, causing the Erlang VM to abort with system_limit and taking down the entire node. This vulnerability does not affect HTTP/1.1, where cowboy derives the scheme from the listener type rather than from a client-supplied header. This issue affects plug_cowboy: from 2.0.0 before 2.8.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • plug.cowboy

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
plug.cowboy

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-27: 3Mentions · 2026-05-06: 1Technical Details · 2026-04-27: 3Technical Details · 2026-05-06: 104-2705-06
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure3
2026-05-061
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 PlugCowboy, Unauthenticated Remote DoS via HTTP/2 Atom-Table Exhaustion, #CVE-2026-32688 (High) https://dailycve.com/plugcowboy-unauthenticated-remote-dos-via-http-2-atom-table-exhaustion-cve-2026-32688-high/

    Post summary

    CVE‑2026‑32688 was disclosed as a high‑severity unauthenticated remote DoS vulnerability affecting HTTP/2 atom‑table handling, but the post contains no proof‑of‑concept, exploit code, or patch information.

    0000037
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32688 Unauthenticated Remote Denial of Service via Atom Table Exhaustion in Elixir-Plug Plug_Cowboy https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32688

    Post summary

    Announces a remote DoS vulnerability (CVE-2026-32688) caused by Atom Table exhaustion in Elixir‑Plug Plug_Cowboy, without providing exploitation details or mitigation.

    0000035
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32688 Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustio… https://www.cve.org/CVERecord?id=CVE-2026-32688

    Post summary

    The post announces CVE‑2026‑32688, a remote denial‑of‑service vulnerability in elixir‑plug plug_cowboy caused by resource exhaustion, but provides no PoC, patch, or active exploitation details.

    0000088
    57.3K followersView on X
  • Elixir Forum@elixirforum
    Disclosure

    [Phoenix Chat] CVE-2026-32688 --- DoS: Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy https://elixirforum.com/t/75147 #PhoenixFramework #ElixirLang #WeBeamTogether #MyElixirStatus

    Post summary

    The tweet discloses CVE‑2026‑32688 as a denial‑of‑service flaw in plug_cowboy triggered by an HTTP/2 :scheme pseudo‑header, leading to atom table exhaustion. It provides technical details but no PoC, exploit code, or patch information.

    00000150
    6.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelixir-plugplug.cowboy---

Explore more