Threats Tagged 'cve-2026-43966'
View all threats tagged with 'cve-2026-43966'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-43966'
Click on any threat for detailed analysis and mitigation recommendations
0 An HTTP Request/Response Splitting vulnerability (CWE-113) exists in the cowlib library used by cowboy and gun. The vulnerability arises because the encoder escapes only backslash and double quote characters but allows other bytes, including CR and LF, to pass through. This mismatch with the parser's expectations enables an attacker to inject CRLF sequences into HTTP headers, potentially splitting the response. This affects cowlib versions prior to 2.16.0. Join the discussion | GCVE Database | 06/08/2026, 18:31:51 UTC Added: 06/19/2026, 19:06:19 UTC |
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values. cow_http_struct_hd:escape_string/2 in cowlib only escapes \ and ", passing all other bytes through verbatim. This creates an encoder/decoder asymmetry: the matching parser accepts only printable ASCII (0x20–0x7E, excluding " and \), but the encoder emits any byte including CR and LF. An application that builds a structured HTTP header via cow_http_struct_hd:item/1 (or a higher-level wrapper such as cow_http_hd:wt_protocol/1) from attacker-controlled input can have \r\n injected into the serialized header value. Once on the wire, the injected CRLF terminates the current header and any following bytes are interpreted as a new header, enabling HTTP response splitting. This issue affects cowlib from 2.9.0. Join the discussion | CVE Database V5 | 06/08/2026, 16:34:33 UTC Added: 06/08/2026, 17:06:22 UTC |
Showing 1 to 2 of 2 results