VYPR
Medium severity5.3NVD Advisory· Published Jun 8, 2026· Updated Aug 17, 2026

CVE-2026-43966

CVE-2026-43966

Description

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values.

cow_http_struct_hd:escape_string/2 in cowlib only escapes \ and ", passing all other bytes through verbatim. This creates an encoder/decoder asymmetry: the matching parser accepts only printable ASCII (0x20–0x7E, excluding " and \), but the encoder emits any byte including CR and LF. An application that builds a structured HTTP header via cow_http_struct_hd:item/1 (or a higher-level wrapper such as cow_http_hd:wt_protocol/1) from attacker-controlled input can have \r\n injected into the serialized header value. Once on the wire, the injected CRLF terminates the current header and any following bytes are interpreted as a new header, enabling HTTP response splitting.

This issue affects cowlib from 2.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cowboyHex
< 2.16.02.16.0
gunHex
< 2.16.02.16.0

Affected products

3
  • Ninenines/Gunreferences
  • Ninenines/Cowlib2 versions
    cpe:2.3:a:ninenines:cowlib:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ninenines:cowlib:*:*:*:*:*:*:*:*range: >=2.9.0,<2.16.0
    • (no CPE)range: from 2.9.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.