Junglewise Threat Intelligence

CVE-2026-43968: ninenines cowlib CRLF injection in SSE encoder

CVE-2026-43968 · Severity: medium · CVSS 4 · Published 2026-05-11

Technologies: Ninenines Cowlib. Vendors: Nine Nines.

Executive brief

A vulnerability in the cowlib library, which is used to handle web protocols in Erlang-based applications, could allow attackers to inject malicious data into Server-Sent Events (SSE). By including special hidden characters in data fields, an attacker can trick a user's web browser into executing unauthorized commands or displaying fake information. This could lead to security bypasses or malicious scripts running in a user's browser session.

Technical details

A CRLF injection vulnerability exists in cowlib's SSE encoder (cow_sse:event/1). While the library sanitizes newline characters (\n), it fails to properly handle carriage return characters (\r) in the id, event, data, and comment fields. Because the SSE specification treats \r, \n, and \r\n as equivalent line terminators, an attacker can use a bare \r to inject new SSE lines. This allows for 'event splitting,' where an attacker can forge entirely new events with arbitrary types and payloads. If the receiving client (such as a browser's EventSource) renders this data in the DOM, it can result in stored XSS or logic manipulation. The issue is fixed in version 2.16.1.

Affected products

  • ninenines cowlib 2.6.0 to 2.16.0

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory
  • 2026-05-11: patched: Fixed in version 2.16.1

References

Related threats