logo

Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed

ID: 82dd73d1-8bb7-5550-8fb2-cdab087a35fc

STIX ID: report--82dd73d1-8bb7-5550-8fb2-cdab087a35fc

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-22

...
...

Multiple critical vulnerabilities were disclosed on 2026-06-08 in Fedora's Erlang packages erlang-gun and erlang-cowboy (CVE-2026-43972, CVE-2026-43973, CVE-2026-43974). Issues include a cross-origin cookie injection that can lead to session fixation and account takeover, plus Denial of Service flaws; affected versions include erlang-gun 2.4.0–2.4.1 and erlang-cowboy 2.16.0–2.16.1 on Fedora 43 and 44, and users are urged to apply updates via dnf immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.