cowboy and gun affected by an HTTP Request/Response Splitting vulnerability (CVE-2026-43966)
An HTTP Request/Response Splitting vulnerability (CWE-113) exists in the cowlib library used by cowboy and gun. The vulnerability arises because the encoder escapes only backslash and double quote characters but allows other bytes, including CR and LF, to pass through. This mismatch with the parser's expectations enables an attacker to inject CRLF sequences into HTTP headers, potentially splitting the response. This affects cowlib versions prior to 2.16.0.
AI Analysis
Technical Summary
The vulnerability in cowlib (affecting cowboy and gun) is due to improper neutralization of CRLF sequences in HTTP headers. Specifically, the function cow_http_struct_hd:escape_string/2 escapes only backslash and double quote characters but passes other bytes verbatim, including carriage return (CR) and line feed (LF). The corresponding parser accepts only printable ASCII characters excluding backslash and double quote, creating an asymmetry. An attacker can exploit this by injecting CRLF sequences into structured HTTP header values constructed from attacker-controlled input, causing HTTP response splitting. This issue affects cowlib versions before 2.16.0.
Potential Impact
Successful exploitation allows an attacker to inject CRLF sequences into HTTP headers, enabling HTTP response splitting. This can lead to HTTP header injection attacks, potentially allowing cache poisoning, cross-site scripting (XSS), or other HTTP response manipulation attacks. The severity is medium based on the CVSS vector provided.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix is referenced, users should monitor the Microsoft Security Response Center advisory for updates. Until a fix is available, avoid using attacker-controlled input in structured HTTP header fields constructed via cow_http_struct_hd:item/1 or related functions.
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability (CVE-2026-43966)
Description
An HTTP Request/Response Splitting vulnerability (CWE-113) exists in the cowlib library used by cowboy and gun. The vulnerability arises because the encoder escapes only backslash and double quote characters but allows other bytes, including CR and LF, to pass through. This mismatch with the parser's expectations enables an attacker to inject CRLF sequences into HTTP headers, potentially splitting the response. This affects cowlib versions prior to 2.16.0.
CVSS v4.0
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in cowlib (affecting cowboy and gun) is due to improper neutralization of CRLF sequences in HTTP headers. Specifically, the function cow_http_struct_hd:escape_string/2 escapes only backslash and double quote characters but passes other bytes verbatim, including carriage return (CR) and line feed (LF). The corresponding parser accepts only printable ASCII characters excluding backslash and double quote, creating an asymmetry. An attacker can exploit this by injecting CRLF sequences into structured HTTP header values constructed from attacker-controlled input, causing HTTP response splitting. This issue affects cowlib versions before 2.16.0.
Potential Impact
Successful exploitation allows an attacker to inject CRLF sequences into HTTP headers, enabling HTTP response splitting. This can lead to HTTP header injection attacks, potentially allowing cache poisoning, cross-site scripting (XSS), or other HTTP response manipulation attacks. The severity is medium based on the CVSS vector provided.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix is referenced, users should monitor the Microsoft Security Response Center advisory for updates. Until a fix is available, avoid using attacker-controlled input in structured HTTP header fields constructed via cow_http_struct_hd:item/1 or related functions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-43966
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a35932bf198dc38c10621a0
Added to database: 06/19/2026, 19:06:19 UTC
Last enriched: 07/30/2026, 15:19:03 UTC
Last updated: 08/02/2026, 07:17:57 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.