CVE-2026-43969

low
Published 2026-05-11 · Modified 2026-05-18
CVSS v3
3.2
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CVSS v2
VIR risk
3.2

Description

cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

Predictions

Exploit likelihood
33%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43969

vendor Authored 2026-05-27

Vendor advisory: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db — https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144

vendor Authored 2026-05-27

Vendor advisory: 6b3ad84c-e1a6-4bf7-a703-f496b71e49db — https://cna.erlef.org/cves/CVE-2026-43969.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
Hexcowlib>=2.9.0
Hexcowlib>=2.9.0,<=2.16.1
ERLANGcowlib>= 2.9.0, <= 2.16.1

Application impact

VendorProductVersionsFixed
nineninescowlib{"startIncluding":"2.9.0","endIncluding":"2.16.1"}

References

CWEs

CWE-93

Verify integrity in audit chain (admin only). AS-IS.