Cowboy 2.20, Cowlib 2.21, Gun 2.7
2026 08 Oct
Cowboy 2.20.0, Cowlib 2.21.0 and Gun 2.7.0 have been released.
They are maintenance releases containing security and bug fixes, so all users are encouraged to upgrade. Cowboy and Gun update Cowlib to 2.21 and must be upgraded along with it.
The obsolete x-webkit-deflate-frame Websocket extension is no longer negotiated. An offer of that extension is ignored. Clients that offered only x-webkit-deflate-frame now get an uncompressed connection. permessage-deflate is unchanged.
Cookie parsing and building now follow the current RFC6265bis draft. Cowboy no longer sends the obsolete Expires attribute in Set-Cookie headers. Gun rejects a SameSite=None cookie that is not Secure.
These releases only support Erlang/OTP 27 and above.
Expect a few more security oriented releases in the near future. They will address increased threats from AI agents usage. Please refer to the companion post explaining the security strategy for more details.
A detailed list of changes can be found in the Cowboy migration guide and the Gun migration guide.
You can donate to these projects via GitHub Sponsors.
As usual, feedback is appreciated, and issues or questions should be sent via Github tickets or discussions. We also have a Discord server. Join Erlang OSS Discord now!

