CVE-2026-43969
CVE-2026-43969 is a low-severity vulnerability in Ninenines Cowlib with a CVSS 3.x base score of 3.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-93.
Key facts
- Severity: Low (CVSS 3.x base score 3.2)
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (10th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-29193
- Weakness: CWE-93
- Affected product: Ninenines Cowlib
- Published:
- Last modified:
Description
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check. This issue affects cowlib: from 2.9.0 onward.
Frequently asked questions
- What is CVE-2026-43969?
- Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check. This issue affects cowlib: from 2.9.0 onward.
- How severe is CVE-2026-43969?
- CVE-2026-43969 has a CVSS 3.x base score of 3.2, rated low severity. It is exploitable over local access with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-43969 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (10th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-43969?
- CVE-2026-43969 affects Ninenines Cowlib. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-43969?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-43969 have an EU (EUVD) identifier?
- Yes. CVE-2026-43969 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-29193.
- When was CVE-2026-43969 published?
- CVE-2026-43969 was published on 2026-05-11 and last updated on 2026-08-18.
References
- https://cna.erlef.org/cves/CVE-2026-43969.html
- https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144
- https://osv.dev/vulnerability/EEF-CVE-2026-43969
Affected products (1)
- cpe:2.3:a:ninenines:cowlib:*:*:*:*:*:*:*:*
More vulnerabilities in Ninenines Cowlib
- CVE-2026-7790 — High (CVSS 7.5): Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive…
- CVE-2026-43966 — Medium (CVSS 5.3): Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in…
- CVE-2026-43968 — Medium (CVSS 4.0): Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event…
All CVEs affecting Ninenines Cowlib →
Other CWE-93 (CRLF Injection) vulnerabilities
- CVE-2026-77550 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability…
- CVE-2024-51501 — Critical (CVSS 10.0): Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit…
- CVE-2026-100717 — Critical (CVSS 9.9): froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return…
- CVE-2026-90937 — Critical (CVSS 9.9): froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated…
- CVE-2026-70615 — Critical (CVSS 9.9): boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users…
- CVE-2026-45372 — Critical (CVSS 9.9): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's…