Origin Validation Error in ninenines gun HTTP/2 Module Allows Cookie Injection
CVE-2026-43972

6.3MEDIUM

Key Information:

Vendor

Ninenines

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-43972?

The vulnerability in the ninenines gun HTTP/2 module arises from an origin validation error that exposes systems to cross-origin cookie injection. This flaw occurs when the :authority pseudo-header in a PUSH_PROMISE frame is stored without proper validation, leading to compromised security. An attacker controlling an HTTP/2 server can exploit this weakness to inject cookies into the client's shared cookie store for third-party domains, enabling session fixation attacks and potentially resulting in unauthorized access to user accounts. The issue is present in versions of gun from 2.0.0 to just before 2.4.0, highlighting the severe implications of unvalidated server responses.

Affected Version(s)

gun 2.0.0 < 2.4.0

gun 871989eef53663285c165fdfb83a5918ebe00d41 < 567863ff53802fed21c3b3f25812db7f7ae29676

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Loïc Hoguin
.