CVE-2026-43971

EUVD-2026-60573
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1.

cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins.

This issue affects cowlib: from 2.9.0 before 2.20.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
EEFCNA
6.3 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.38%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nineninescowlib
2.9.0 ≤
𝑥
< 2.20.0
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
erlang-cowlib
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rabbitmq-server
Azure Linux 3.0
0:3.13.7-9.azl3
fixed