CVE-2026-43970

high
Published 2026-05-13 · Modified 2026-05-19
CVSS v3
CVSS v2
VIR risk
8.0

Description

cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43970

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
Hexcowlib>=0.1.0,<2.16.12.16.1
ERLANGcowlib>= 0.1.0, < 2.16.12.16.1

References

CWEs

CWE-409

Verify integrity in audit chain (admin only). AS-IS.