{"id":"CVE-2026-43969","title":"Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.\n\ncow_cookie:cookie/1 in cowlib builds a clien…","summary":"Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.\n\ncow_cookie:cookie/1 in cowlib builds a clien…","severity":"low","cvss":3.2,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","cwe":["CWE-93"],"vendor":"ninenines","product":"cowlib","affected":["cowlib >= 2.9.0, <= 2.16.1"],"published":"2026-05-11","updated":"2026-08-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-43969","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-43969.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-43969","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"tags":["nvd"],"epss":0.00146,"epssPercentile":0.0422,"ingestedAt":"2026-08-18T15:19:01.999Z","slug":"CVE-2026-43969","body":"## Overview\n\nImproper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.\n\ncow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check.\n\nThis issue affects cowlib: from 2.9.0 onward.\n\n## Affected\n\n- `cowlib >= 2.9.0, <= 2.16.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":17.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}