Origin Validation Error in ninenines gun HTTP/2 Module Allows Cookie Injection
CVE-2026-43972
What is CVE-2026-43972?
The vulnerability in the ninenines gun HTTP/2 module arises from an origin validation error that exposes systems to cross-origin cookie injection. This flaw occurs when the :authority pseudo-header in a PUSH_PROMISE frame is stored without proper validation, leading to compromised security. An attacker controlling an HTTP/2 server can exploit this weakness to inject cookies into the client's shared cookie store for third-party domains, enabling session fixation attacks and potentially resulting in unauthorized access to user accounts. The issue is present in versions of gun from 2.0.0 to just before 2.4.0, highlighting the severe implications of unvalidated server responses.
Affected Version(s)
gun 2.0.0 < 2.4.0
gun 871989eef53663285c165fdfb83a5918ebe00d41 < 567863ff53802fed21c3b3f25812db7f7ae29676
