CRLF Injection Vulnerability in ninenines' Cowlib Product
CVE-2026-43969

2.1LOW

Key Information:

Vendor

Ninenines

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-43969?

The cowlib library developed by ninenines is vulnerable due to improper handling of CRLF sequences within cookie name and value fields. This deficiency allows attackers to perform cookie smuggling and HTTP request splitting attacks. Specifically, an adversary can manipulate cookie headers by injecting CR, LF, TAB, or separator characters, leading to unauthorized actions such as introducing phantom cookies that can be mistaken for legitimate ones by the server. Consequently, this vulnerability poses a significant risk when unvalidated cookie information is processed, as it permits the attacker to execute malicious HTTP headers or relay an entire second request through a shared upstream proxy.

Affected Version(s)

cowlib 2.9.0

cowlib f017f8a0ecbffd5033d9ab49bf180186f7a523a7

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
.