Improper Encoding Vulnerability in Cowlib by Erlang Solutions
CVE-2026-43971

6.3MEDIUM

Key Information:

Vendor

Ninenines

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-43971?

The improper encoding or escaping of output in Cowlib allows attackers to exploit Link header directives by injecting unescaped special characters. This vulnerability enables attackers to smuggle malicious Link headers, influencing browser behavior and potentially directing users to compromised destinations. By manipulating the interpolation of the target URI, rel values, and attribute keys into the serialized Link header, an attacker can manipulate browsers into making unintended connections to their controlled origins. This flaw affects all versions of Cowlib from 2.9.0 onward.

Affected Version(s)

cowlib 2.9.0

cowlib 485d58dfa91b91d98135dc95e5615f421715dae5

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
.