—Hex
EEF-CVE-2026-43972· CVE-2026-43972, GHSA-36w4-95hv-5vwggun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
Modified: 9/8/2026
package
pkg:hex/gun
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
Modified: 9/8/2026
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
Modified: 8/3/2026
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
Modified: 8/3/2026
gun has an Unexpected Status Code or Return Value vulnerability
Modified: 7/29/2026
gun_http2 has an Origin Validation Error vulnerability
Modified: 7/29/2026
gun has an Uncontrolled Resource Consumption vulnerability
Modified: 7/29/2026
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
Modified: 9/10/2026