- Package:
- src:erlang-cowlib
- Source:
- src:erlang-cowlib
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-12 16:53:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for erlang-cowlib. CVE-2026-43971[0]: | Improper Encoding or Escaping of Output vulnerability in ninenines | cowlib allows Link header directive smuggling via unescaped special | characters in cow_link:link/1. cow_link:do_link/1 in cowlib | interpolates the target URI, rel value, and attribute keys directly | into the serialized Link: header value without escaping or token- | grammar validation. A > byte in target prematurely closes the URI | slot, allowing an attacker to append additional link entries with | attacker-chosen rel directives. A " or \ in rel escapes the quoted | string and opens new parameters. Any byte — including whitespace, =, | and " — in an attribute key is emitted verbatim. Because browsers | act on Link: directives such as rel="preconnect", rel="preload", and | rel="prerender", an attacker who can influence these fields in an | application that round-trips parsed Link headers through | cow_link:link/1 can force victim browsers to make out-of-band | connections to attacker-controlled origins. This issue affects | cowlib: from 2.9.0 onward. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-43971 https://www.cve.org/CVERecord?id=CVE-2026-43971 [1] https://cna.erlef.org/cves/CVE-2026-43971.html [2] https://osv.dev/vulnerability/EEF-CVE-2026-43971 [3] https://github.com/ninenines/cowlib/commit/89da27ee4c241f5d649ba7d9b7f2188918af6cea Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
erlang-cowlib, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145197@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sergei Golovan <sgolovan@debian.org> (supplier of updated erlang-cowlib package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 19:28:04 +0300
Source: erlang-cowlib
Architecture: source
Version: 2.20.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan@debian.org>
Closes: 1145197
Changes:
erlang-cowlib (2.20.0-1) unstable; urgency=medium
.
* New upstream release.
- Fix CVE-2026-43971: Improper Encoding or Escaping of Output
vulnerability in ninenines cowlib allows Link header directive smuggling
via unescaped special characters in cow_link:link/1 (closes: #1145197).
* Drop the priority field from debian/control.
Checksums-Sha1:
c28ac7c23bb7fcfc59698accbecf9b87be3069b6 2137 erlang-cowlib_2.20.0-1.dsc
be4e082fc9e7eb4bc6b390d0263b310b234eb710 218413 erlang-cowlib_2.20.0.orig.tar.gz
29ae49c0e0329a6baac1ea0378ffdbb2138b1022 3344 erlang-cowlib_2.20.0-1.debian.tar.xz
64635d0f2b316b22718383cd85f7eab31cec3446 6107 erlang-cowlib_2.20.0-1_amd64.buildinfo
Checksums-Sha256:
6da4852f7bc38b8a938a866dce4ff304a2b8738bc174081296235bc5eb504fa4 2137 erlang-cowlib_2.20.0-1.dsc
18357c83b82bc941dbe8b64e85763e5820649913a2a2200a690f546af3b3234f 218413 erlang-cowlib_2.20.0.orig.tar.gz
70e9181e556d3f92184f1ff82cd438cc4ce306eec7ccabe468a3c5b7a51ee370 3344 erlang-cowlib_2.20.0-1.debian.tar.xz
1b3bb27803b693776e3737c7f0310ad7007a35bc67870f7ef0b17a15d9da24e5 6107 erlang-cowlib_2.20.0-1_amd64.buildinfo
Files:
a45ff0f4bb9620db925d1c74fdf26fc4 2137 devel optional erlang-cowlib_2.20.0-1.dsc
7899e77fe08fc272e9af838cdcde2d94 218413 devel optional erlang-cowlib_2.20.0.orig.tar.gz
f481fea72d3b56caa93f73aa75a012dd 3344 devel optional erlang-cowlib_2.20.0-1.debian.tar.xz
d535d0917560d8a5ad5b8e8fbc02c516 6107 devel optional erlang-cowlib_2.20.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqlfdwACgkQTyrk60tj
54ePEhAAxxOwtGFrpkcB6oe7+OlZfFofvHx4AbIJDaypusczZv7Xzw+1DP5sf49F
24J16bZDgVAkykpCYVlj5Ubicord9ouIceXjhzBCxEfWptZ4WxLC+pP7wPRI6TDI
2QTMZa6ja58t1FDkZgcDhjPOa7w1JDgrhrRKdYfDfQUa8Zy29qzsrNoBEc6dttBo
4hg7La8WFdIWrJ+wn/dDdzYo7IcIGHXM6OPP7jLuQvSaZsJSW4hMYPZosdDk2Pyv
3xRJdLkDGXpVMzHAfF2qgmeLHuoB/TecWFD8ieHzZZmbbxRffUndo1wgywOlGv7a
BBZrbQI2loZsniBRNSzdYktbJm6nyS+gdlOtkHNAPX1B5soG7zt4IX5bm4rbP+ls
87RChGxcqOliN+JVoxp4mV/rEp1ybyOtxzvX6KCQo0hGyvw32v2fnEkcx5i/S1xr
+QXfKGZ6hKA3NtdL7YoSDLsQZT4czJRAJJ5rvSdPD8VY/P4GLQVJACs2bsIYf6cr
ylrtQAnomCnlNxaH7R1djg41QPB+ovGJKA9bD2x/1VyThXPx5g5LbouvGFfP5ZeA
rr7UO9QBejGQlTW+IWEEwnf0EUOV9qiade0qAfR/gYzbtdO4XzwmN9TU8lGEVZ2z
0swjO9Tyv6BAlEQF8W83Hx4IEGY7+5oodLWTx9iqG1Q1DT+AAaE=
=TvGe
-----END PGP SIGNATURE-----