Executive brief
A vulnerability in the Plug library, a core component for Elixir web applications, allows attackers to crash or slow down a server by sending specially crafted file upload requests. By sending many empty files in a single request, an attacker can bypass size limits to exhaust the server's disk space and memory. This can lead to a total service outage for any application that handles file uploads or multipart forms using this library.
Technical details
A resource exhaustion vulnerability exists in Plug.Parsers.MULTIPART due to improper enforcement of the ':length' budget. The parser only counts body bytes toward the limit, ignoring header bytes and treating empty-body parts as zero-cost. Because each part with a filename triggers the creation of a temporary file and a corresponding 'Plug.Upload' struct, an attacker can send a single HTTP request containing thousands of empty file parts. This bypasses default size limits to cause inode exhaustion, disk space depletion, and unbounded memory growth. The issue is fixed in versions 1.16.6, 1.17.4, 1.18.5, 1.19.5, and 1.20.3.
Affected products
- elixir-plug plug from 1.4.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.0 before 1.19.5, and from 1.20.0 before 1.20.3
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://repo.hex.pm/
- https://github.com/
- https://cna.erlef.org/cves/CVE-2026-56814.html
- https://github.com/elixir-plug/plug/commit/0ee8afcc61466dc5f7a8f048d0632c899165b81f
- https://github.com/elixir-plug/plug/commit/56edca2ce35fe5589cd581644d8a4493fa5f484e
- https://github.com/elixir-plug/plug/commit/981597d3a4271ede64373c7a731702a42c500dd6
- https://github.com/elixir-plug/plug/commit/cae36053350e5215a4e0ca33cd130af9c5fc6364