Ninenines

Cowlib

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 18.08.2026 09:01:53
  • Zuletzt bearbeitet 20.08.2026 13:02:12

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute ...

  • EPSS 0.29%
  • Veröffentlicht 28.07.2026 10:16:50
  • Zuletzt bearbeitet 30.07.2026 19:14:09

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-intege...

  • EPSS 0.25%
  • Veröffentlicht 08.06.2026 16:34:33
  • Zuletzt bearbeitet 17.08.2026 17:56:14

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values. cow_http_struct_hd:escape_string/2...

  • EPSS 0.27%
  • Veröffentlicht 11.05.2026 18:06:42
  • Zuletzt bearbeitet 21.05.2026 13:59:07

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. cow_sse:event/1 in cowlib guards the id and event fields against \n but not against...

  • EPSS 0.43%
  • Veröffentlicht 11.05.2026 18:06:41
  • Zuletzt bearbeitet 13.05.2026 15:57:03

Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. Each digit c...

  • EPSS 0.15%
  • Veröffentlicht 11.05.2026 18:06:40
  • Zuletzt bearbeitet 18.08.2026 12:19:14

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie...