Description
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.

cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check.

This issue affects cowlib: from 2.9.0 onward.
Published: 2026-05-11
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of CRLF Sequences (CWE-93) in the cow_cookie:cookie/1 function of the cowlib Erlang library permits an attacker who can control the cookie name or value fields to inject CR, LF, semicolons, commas, or tabs into a serialized Cookie header. Based on the description, it is inferred that this manipulation can result in cookie smuggling—for example, adding "; admin=1" to forge an authenticated cookie—or HTTP request header splitting, which appends unauthorized headers or a complete second request to a shared upstream proxy. The effect is a violation of confidentiality, integrity, or availability of downstream applications, potentially enabling unauthorized authentication or request tampering.

Affected Systems

The vulnerability affects the cowlib Erlang library developed by ninenines. It is present in versions 2.9.0 and later that have not applied the encoder validation patch. Any application that uses cow_cookie:cookie/1 to construct outbound Cookie headers – such as web servers, HTTP clients, or reverse proxies relying on cowlib – should be evaluated for exposure.

Risk and Exploitability

The CVSS score of 2.1 labels this issue as low severity, and the EPSS score of less than 1 percent indicates a very limited likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires an attacker to influence the arguments passed to cow_cookie:cookie/1, typically by compromising application logic or supplying crafted user input. Because the defect resides solely in the encoder, the attack surface is constrained to outbound request construction. Nonetheless, the presence of CRLF or other delimiters can lead to authentication bypass or defacement if downstream services are not stringent about header validation.

Generated by OpenCVE AI on August 18, 2026 at 13:28 UTC.

Remediation

Vendor Workaround

Validate inputs into cow_cookie:cookie/1 to only include valid cookie name and value characters as defined in RFC 6265 Section 4.1.1 before passing them to the function.


OpenCVE Recommended Actions

  • Upgrade cowlib to the latest version that contains the encoder validation fix for cookie names and values.
  • Validate any input passed to cow_cookie:cookie/1 against RFC 6265 Section 4.1.1, allowing only characters permitted for cookie names and values before calling the function.
  • Implement monitoring or logging for unexpected CR or LF sequences in outgoing Cookie headers to detect potential injection attempts.

Generated by OpenCVE AI on August 18, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g2wm-735q-3f56 cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
History

Tue, 18 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting "; admin=1" to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check. This issue affects cowlib from 2.9.0. Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting ; admin=1 to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check. This issue affects cowlib: from 2.9.0 onward.

Thu, 21 May 2026 14:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Mon, 11 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting "; admin=1" to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check. This issue affects cowlib from 2.9.0.
Title Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
First Time appeared Ninenines
Ninenines cowlib
Weaknesses CWE-93
CPEs cpe:2.3:a:ninenines:cowlib:*:*:*:*:*:*:*:*
Vendors & Products Ninenines
Ninenines cowlib
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Ninenines Cowlib
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-18T11:26:01.022Z

Reserved: 2026-05-04T18:23:25.573Z

Link: CVE-2026-43969

cve-icon Vulnrichment

Updated: 2026-05-11T18:55:21.472Z

cve-icon NVD

Status : Modified

Published: 2026-05-11T19:16:25.330

Modified: 2026-08-18T12:19:14.863

Link: CVE-2026-43969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')