cowlib
Hex7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cowlibpage 1 of 1
- CVE-2026-43966MEDIUMCVSS 5.3EG 5.32026-06-08
vulnerable: 2.10.0 ... 2.9.1 (16 versions)
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values. cow_http_struct_hd:esca…
- CVE-2026-43968MEDIUMCVSS 4.0EG 4.0✓ Fixed in 2.16.12026-05-11
vulnerable: 2.10.0 ... 2.9.1 (17 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. cow_sse:event/1 in cowlib guards the id and event fields against \n but …
- CVE-2026-43969LOWCVSS 3.2EG 3.22026-05-11
vulnerable: 2.10.0 ... 2.9.1 (12 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-…
- CVE-2026-43970HIGHCVSS 8.2EG 8.2✓ Fixed in 2.16.12026-05-13
vulnerable: 1.0.0 ... 2.9.1 (32 versions)
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes d…
- CVE-2026-43971MEDIUMCVSS 6.3EG 6.32026-08-18
vulnerable: 2.10.0 ... 2.9.1 (16 versions)
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and…
- CVE-2026-59248HIGHCVSS 8.7EG 8.7✓ Fixed in 2.19.02026-07-28
vulnerable: 2.0.0 ... 2.9.1 (30 versions)
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK pref…
- CVE-2026-7790HIGHCVSS 8.7EG 8.7✓ Fixed in 2.16.12026-05-11
vulnerable: 1.0.0 ... 2.9.1 (32 versions)
Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. E…
Check whether cowlib is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cowlib CVEs against the assets you own.
Start Free Scan →