Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed
ID: 82dd73d1-8bb7-5550-8fb2-cdab087a35fc
STIX ID: report--82dd73d1-8bb7-5550-8fb2-cdab087a35fc
Feed Name: ThreatCluster
Threat Score
Multiple critical vulnerabilities were disclosed on 2026-06-08 in Fedora's Erlang packages erlang-gun and erlang-cowboy (CVE-2026-43972, CVE-2026-43973, CVE-2026-43974). Issues include a cross-origin cookie injection that can lead to session fixation and account takeover, plus Denial of Service flaws; affected versions include erlang-gun 2.4.0–2.4.1 and erlang-cowboy 2.16.0–2.16.1 on Fedora 43 and 44, and users are urged to apply updates via dnf immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
