CVE-2026-43968

medium
Published 2026-05-11 · Modified 2026-05-18
CVSS v3
4.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS v2
VIR risk
4.0

Description

ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values

Predictions

Exploit likelihood
50%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43968

vendor Authored 2026-05-27

Vendor advisory: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db — https://github.com/ninenines/cowlib/commit/6165fc40efa159ba1cceee7e7981e790acba5d9c

vendor Authored 2026-05-27

Vendor advisory: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db — https://cna.erlef.org/cves/CVE-2026-43968.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
Hexcowlib>=2.6.0,<2.16.12.16.1
ERLANGcowlib>= 2.6.0, < 2.16.12.16.1

Application impact

VendorProductVersionsFixed
nineninescowlib{"startIncluding":"2.6.0","endExcluding":"2.16.1"}2.16.1

References

CWEs

CWE-93

Verify integrity in audit chain (admin only). AS-IS.