« Volver al listado

CVE-2026-58226

Estado: AplazadaAlta (8.7)—

Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding.

hpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3 accumulates the integer as int + (value <<< m), shifting by 7 more bits for each continuation octet and stopping only on a terminating octet or truncated input, never because the integer grew too large.

Leer descripción completaMostrar menos

Because BEAM integers are arbitrary precision, a run of N continuation octets builds an O(N)-bit bignum and re-adds into an ever-larger bignum on each step, so the total decoding cost is superlinear (about O(N^2)). An unauthenticated attacker who can send an HTTP/2 header block to a server using this decoder (reached through the 'Elixir.HPAX':decode/2 entry point) can supply a small header block that forces a large, attacker-controlled amount of CPU (and transient memory), a denial-of-service amplification.

This issue affects hpax from 0.1.1 before 1.0.4.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE-2026-58226 es una vulnerabilidad de acceso remoto sin autenticación (AV:N/PR:N/UI:N) que permite DoS por complejidad algorítmica en decodificación HPACK HTTP/2; encaja en T1190 (explotación de aplicación expuesta) e impacto T1499.004 (consumo CPU).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-58226",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-58226",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-06T12:49:38.954923Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:elixir-mint:hpax:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-mint/hpax",
          "vendor": "elixir-mint",
          "modules": [
            "Elixir.HPAX",
            "Elixir.HPAX.Types"
          ],
          "product": "hpax",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.1",
              "lessThan": "1.0.4",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:hex/hpax",
          "packageName": "hpax",
          "programFiles": [
            "lib/hpax.ex",
            "lib/hpax/types.ex"
          ],
          "collectionURL": "https://repo.hex.pm",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.HPAX':decode/2"
            },
            {
              "name": "'Elixir.HPAX.Types':decode_integer/2"
            },
            {
              "name": "'Elixir.HPAX.Types':decode_remaining_integer/3"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:elixir-mint:hpax:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/elixir-mint/hpax",
          "vendor": "elixir-mint",
          "modules": [
            "Elixir.HPAX",
            "Elixir.HPAX.Types"
          ],
          "product": "hpax",
          "versions": [
            {
              "status": "affected",
              "version": "56db437a7e2c515e3bdd770ac7947b02cd2390d0",
              "lessThan": "1ba4bb2dc91e80089cf89c73970ac3ded76f17eb",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/elixir-mint/hpax",
          "packageName": "elixir-mint/hpax",
          "programFiles": [
            "lib/hpax.ex",
            "lib/hpax/types.ex"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "'Elixir.HPAX':decode/2"
            },
            {
              "name": "'Elixir.HPAX.Types':decode_integer/2"
            },
            {
              "name": "'Elixir.HPAX.Types':decode_remaining_integer/3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-06T11:16:31.143",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-58226.html",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/hpax/commit/1ba4bb2dc91e80089cf89c73970ac3ded76f17eb",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/hpax/security/advisories/GHSA-jj2p-32j7-whj2",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-58226",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/elixir-mint/hpax/security/advisories/GHSA-jj2p-32j7-whj2",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-407"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding.\n\nhpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3 accumulates the integer as int + (value <<< m), shifting by 7 more bits for each continuation octet and stopping only on a terminating octet or truncated input, never because the integer grew too large. Because BEAM integers are arbitrary precision, a run of N continuation octets builds an O(N)-bit bignum and re-adds into an ever-larger bignum on each step, so the total decoding cost is superlinear (about O(N^2)). An unauthenticated attacker who can send an HTTP/2 header block to a server using this decoder (reached through the 'Elixir.HPAX':decode/2 entry point) can supply a small header block that forces a large, attacker-controlled amount of CPU (and transient memory), a denial-of-service amplification.\n\nThis issue affects hpax from 0.1.1 before 1.0.4."
    }
  ],
  "lastModified": "2026-07-06T19:37:48.003",
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}