CVE-2026-43971
Last modified
CVE-2026-43971 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins. This issue affects cowlib: from 2.9.0 before 2.20.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ninenines | cowlib | >= 2.9.0, < 2.20.0 |
| ninenines | cowlib | >= 485d58dfa91b91d98135dc95e5615f421715dae5, < 89da27ee4c241f5d649ba7d9b7f2188918af6cea |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-43971?
How severe is CVE-2026-43971?
How do I fix CVE-2026-43971?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43965Path traversal vulnerability in Gleam's dependency managemen…5.6
- CVE-2026-43966Improper Neutralization of CRLF Sequences in HTTP Headers ('…5.3
- CVE-2026-43967Inefficient Algorithmic Complexity vulnerability in absinthe…7.5
- CVE-2026-43968Improper Neutralization of CRLF Sequences ('CRLF Injection')…4
- CVE-2026-43969Improper Neutralization of CRLF Sequences ('CRLF Injection')…3.2
- CVE-2026-43970Improper Handling of Highly Compressed Data (Data Amplificat…8.2
- CVE-2026-43972Origin Validation Error vulnerability in ninenines gun (gun_…7.2
- CVE-2026-43973Uncontrolled Resource Consumption vulnerability in ninenines…7.5
- CVE-2026-43974Unexpected Status Code or Return Value vulnerability in nine…7.5
- CVE-2026-43975FolderUploadsFileManager in Apache Wicket does not validate …6.5
- CVE-2026-43977wger is a free, open-source workout and fitness manager. In …7.5
- CVE-2026-43978wger is a free, open-source workout and fitness manager. In …8.1
Are you affected by CVE-2026-43971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
