{"id":"GHSA-w4f7-4cxr-rv3c","summary":"cowboy and gun affected by an HTTP Request/Response Splitting vulnerability","details":"Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values.\n\ncow_http_struct_hd:escape_string/2 in cowlib only escapes \\ and \", passing all other bytes through verbatim. This creates an encoder/decoder asymmetry: the matching parser accepts only printable ASCII (0x20–0x7E, excluding \" and \\), but the encoder emits any byte including CR and LF. An application that builds a structured HTTP header via cow_http_struct_hd:item/1 (or a higher-level wrapper such as cow_http_hd:wt_protocol/1) from attacker-controlled input can have \\r\\n injected into the serialized header value. Once on the wire, the injected CRLF terminates the current header and any following bytes are interpreted as a new header, enabling HTTP response splitting.\n\nThis issue affects cowlib from 2.9.0.","aliases":["CVE-2026-43966","EEF-CVE-2026-43966"],"modified":"2026-09-15T06:34:26.094033168Z","published":"2026-06-08T18:31:51Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-29T15:48:39Z","nvd_published_at":"2026-06-08T17:16:43Z","cwe_ids":["CWE-113"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43966"},{"type":"WEB","url":"https://github.com/ninenines/cowlib/pull/163#issuecomment-4952645232"},{"type":"WEB","url":"https://github.com/ninenines/cowlib/pull/166#issuecomment-5067554701"},{"type":"WEB","url":"https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef"},{"type":"WEB","url":"https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-43966.html"},{"type":"PACKAGE","url":"https://github.com/ninenines/cowlib"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-43966"}],"affected":[{"package":{"name":"cowboy","ecosystem":"Hex","purl":"pkg:hex/cowboy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.16.0"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.1.0","1.1.1","1.1.2","2.0.0","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.14.2","2.15.0","2.2.0","2.2.1","2.2.2","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.6.2","2.6.3","2.7.0","2.8.0","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w4f7-4cxr-rv3c/GHSA-w4f7-4cxr-rv3c.json"}},{"package":{"name":"gun","ecosystem":"Hex","purl":"pkg:hex/gun"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.16.0"}]}],"versions":["1.0.0","1.0.0-pre.1","1.0.0-pre.2","1.0.0-pre.4","1.0.0-pre.4b","1.0.0-pre.5","1.1.0","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","2.0.0","2.0.0-rc.1","2.0.0-rc.2","2.0.1","2.1.0","2.2.0","2.3.0","2.4.0","2.4.1","2.5.0","2.6.0"],"database_specific":{"last_known_affected_version_range":"\u003c 2.4.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w4f7-4cxr-rv3c/GHSA-w4f7-4cxr-rv3c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}