Loïc Hoguin
11 exploits
Active since May 2026
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CVSS 4.0
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
CVSS 7.5