CVE-2026-8468: Plug Unbounded Multipart Header Accumulation

Internal accumulation of network stream data (`data <> next`) inside a recursive function without checking the `byte_size` against a configured limit. This allows attackers to bypass length restrictions and exhaust server memory (CWE-400, DoS). Ensure an explicit boundary check (`byte_size(data) >= length`) is executed before recursion.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Elixir
greprules fetch cve-2026-8468-plug-unbounded-multipart-header-accumulation --engine opengrep

Description

Internal accumulation of network stream data (`data <> next`) inside a recursive function without checking the `byte_size` against a configured limit. This allows attackers to bypass length restrictions and exhaust server memory (CWE-400, DoS). Ensure an explicit boundary check (`byte_size(data) >= length`) is executed before recursion.