---
id: CVE-2026-43969
title: >-
  Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in
  ninenines cowlib allows HTTP request splitting and cookie smuggling via
  unvalidated cookie name and value fields.


  cow_cookie:cookie/1 in cowlib builds a clien…
summary: >-
  Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in
  ninenines cowlib allows HTTP request splitting and cookie smuggling via
  unvalidated cookie name and value fields.


  cow_cookie:cookie/1 in cowlib builds a clien…
severity: low
cvss: 3.2
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-93
vendor: ninenines
product: cowlib
affected:
  - 'cowlib >= 2.9.0, <= 2.16.1'
published: '2026-05-11'
updated: '2026-08-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43969'
references:
  - url: 'https://cna.erlef.org/cves/CVE-2026-43969.html'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: >-
      https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
  - url: 'https://osv.dev/vulnerability/EEF-CVE-2026-43969'
    label: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.04214
ingestedAt: '2026-08-18T15:19:01.999Z'
---

## Overview

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.

cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check.

This issue affects cowlib: from 2.9.0 onward.

## Affected

- `cowlib >= 2.9.0, <= 2.16.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
