CVE-2026-43968Disclosure(ninenines / cowlib)

LOWCVSS 4.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ninenines cowlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. cow_sse:event/1 in cowlib guards the id and event fields against \n but not against bare \r, and the internal prefix_lines/2 function used for data and comment fields splits only on \n. Because the SSE specification requires decoders to treat \r\n, \r, and \n as equivalent line terminators, an attacker who controls any of these fields can inject additional SSE lines and forge a complete event with an arbitrary event type and data payload on the receiving end. In typical deployments where browser EventSource clients or other SSE consumers dispatch on event.type and render event.data, this enables event splitting, client-side logic manipulation, and stored-XSS-equivalent behaviour when event data is inserted into the DOM. This issue affects cowlib from 2.6.0 before 2.16.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cowlib

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cowlib

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-27: 105-1105-27
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-271
Patch1
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🪟 CRLF SSE event splitting (CVE-2026-43968) is the kind of “not Windows” bug that still ruins your Windows day. Web front ends turning into a fake news factory—patch cowlib 2.16.1. https://windowsforum.com/threads/cve-2026-43968-sse-crlf-event-splitting-patch-cowlib-2-16-1.419876/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WebSecurity #ErlangCowlib #Cve202643968 #ServerSentEvents https://t.co/U5B2adq3Bx

    Post summary

    This post announces that CVE-2026-43968, a CRLF Server Sent Events event‑splitting flaw, is resolved by upgrading cowlib to version 2.16.1.

    0000052
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43968 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. … https://www.cve.org/CVERecord?id=CVE-2026-43968

    Post summary

    The article announces CVE‑2026‑43968, a CRLF injection flaw in ninenines cowlib that permits SSE event splitting and injection, with no PoC, exploit code, or patch referenced.

    0000056
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnineninescowlib---

Explore more