{"id":3512652,"name":"cowlib","ecosystem":"hex","description":"Support library for manipulating Web protocols.","homepage":"https://ninenines.eu/docs/en/cowlib/2.20/manual/","licenses":"ISC","normalized_licenses":["ISC"],"repository_url":"https://github.com/ninenines/cowlib","keywords_array":[],"namespace":null,"versions_count":38,"first_release_published_at":"2014-08-01T16:06:23.000Z","latest_release_published_at":"2026-09-08T14:48:09.329Z","latest_release_number":"2.20.0","last_synced_at":"2026-10-01T22:30:53.689Z","created_at":"2022-04-10T21:21:32.085Z","updated_at":"2026-10-02T21:29:40.775Z","registry_url":"https://hex.pm/packages/cowlib/","install_command":"mix hex.package fetch cowlib","documentation_url":"http://hexdocs.pm/cowlib/","metadata":{},"repo_metadata":{"id":386692,"uuid":"12277452","full_name":"ninenines/cowlib","owner":"ninenines","description":"Support library for manipulating Web protocols.","archived":false,"fork":false,"pushed_at":"2026-09-08T11:11:13.000Z","size":1485,"stargazers_count":298,"open_issues_count":17,"forks_count":192,"subscribers_count":20,"default_branch":"master","last_synced_at":"2026-09-19T22:18:41.980Z","etag":null,"topics":["erlang","http","http2","http3","parser","websocket","webtransport"],"latest_commit_sha":null,"homepage":"","language":"Erlang","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"isc","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ninenines.png","metadata":{"files":{"readme":"README.asciidoc","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"github":"essen","custom":"https://ninenines.eu/services/#_sponsoring"}},"created_at":"2013-08-21T18:02:24.000Z","updated_at":"2026-09-08T09:07:39.000Z","dependencies_parsed_at":"2024-06-18T11:13:40.242Z","dependency_job_id":"ee1838b3-a991-4df3-93dd-baa531d159c8","html_url":"https://github.com/ninenines/cowlib","commit_stats":{"total_commits":388,"total_committers":27,"mean_commits":14.37037037037037,"dds":"0.11340206185567014","last_synced_commit":"1c3d5defba28e92a88ce45c440d57e178ab1c514"},"previous_names":["extend/cowlib"],"tags_count":46,"template":false,"template_full_name":null,"purl":"pkg:github/ninenines/cowlib","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ninenines","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37605549,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-22T02:00:07.665Z","response_time":55,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"ninenines","name":"Nine Nines","uuid":"1166740","kind":"organization","description":"","email":"contact@ninenines.eu","website":"https://ninenines.eu","location":"France","twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/1166740?v=4","repositories_count":19,"last_synced_at":"2024-03-25T21:17:26.251Z","metadata":{"has_sponsors_listing":false,"funding":{"github":"essen","custom":"https://ninenines.eu/services/#_sponsoring"}},"html_url":"https://github.com/ninenines","funding_links":["https://github.com/sponsors/essen","https://ninenines.eu/services/#_sponsoring"],"total_stars":10594,"followers":73,"following":0,"created_at":"2022-11-02T16:43:34.869Z","updated_at":"2024-03-25T21:17:26.746Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ninenines","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ninenines/repositories"},"tags":[{"name":"2.17.1","sha":"2c968bb751132151bce6823743cf9a141a4acca6","kind":"tag","published_at":"2026-06-11T07:47:14.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.17.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.17.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.17.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.17.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.17.1/manifests"},{"name":"2.17.0","sha":"8ec6fdcb563900a1099dffaa8896552e88e12cd6","kind":"tag","published_at":"2026-06-08T10:35:52.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.17.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.17.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.17.0/manifests"},{"name":"2.16.1","sha":"bae6b022af54566f3518a3aa59083b4591d552de","kind":"tag","published_at":"2026-05-12T11:29:44.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.16.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.16.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.16.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.16.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.16.1/manifests"},{"name":"2.16.0","sha":"aca0ad953417b29bab2c41eeb4c37c98606c848b","kind":"tag","published_at":"2025-09-18T09:45:49.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.16.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.16.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.16.0/manifests"},{"name":"2.15.0","sha":"f8d0ad7f19b5dddd33cbfb089ebd2e2be2a81a5d","kind":"tag","published_at":"2025-04-11T10:23:19.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.15.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.15.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.15.0/manifests"},{"name":"2.14.0","sha":"d0ab49ed797e5bb48209825428d26947d74aabd5","kind":"tag","published_at":"2025-02-17T11:42:56.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.14.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.14.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.14.0/manifests"},{"name":"2.13.0","sha":"1eb7f4293a652adcfe43b1835d22c58d8def839f","kind":"tag","published_at":"2024-03-14T11:55:23.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.13.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.13.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.13.0/manifests"},{"name":"2.12.1","sha":"cc04201c1d0e1d5603cd1cde037ab729b192634c","kind":"tag","published_at":"2023-03-29T13:19:02.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.12.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.12.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.12.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.12.1/manifests"},{"name":"2.12.0","sha":"d8e4318300cb9bbf7a2189686b0698392467ba91","kind":"tag","published_at":"2023-01-16T12:38:56.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.12.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.12.0/manifests"},{"name":"2.11.0","sha":"e9448e5628c8c1d9083223ff973af8de31a566d1","kind":"tag","published_at":"2021-04-24T14:29:23.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.11.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.11.0/manifests"},{"name":"2.10.1","sha":"d06fcad11a00be1c56d0a76e1c46c45b1ff71edd","kind":"tag","published_at":"2020-11-19T12:09:12.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.10.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.10.1/manifests"},{"name":"2.10.0","sha":"c20c37dec04f6d27382c7e754f2ba74d4faec517","kind":"tag","published_at":"2020-11-06T12:28:12.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.10.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.10.0/manifests"},{"name":"2.9.1","sha":"1b5539a1da1d39b110d81b118000f00bbedaf4b4","kind":"tag","published_at":"2020-04-01T18:08:53.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.9.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.9.1/manifests"},{"name":"2.9.0","sha":"b34155f725245848dca3a505398e262b1d50f25b","kind":"tag","published_at":"2020-03-25T11:16:12.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.9.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.9.0/manifests"},{"name":"2.8.0","sha":"c6553f8308a2ca5dcd69d845f0a7d098c40c3363","kind":"tag","published_at":"2019-10-10T16:56:55.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.8.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.8.0/manifests"},{"name":"2.7.3","sha":"75aaeb8415033b07303febbfeba66d6d3413ad06","kind":"tag","published_at":"2019-04-05T08:54:32.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.7.3","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.7.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.3/manifests"},{"name":"2.7.2","sha":"ad005b7d96441826a6fad1f6473ce69d11f53ca4","kind":"tag","published_at":"2019-04-04T09:10:34.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.7.2","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.2/manifests"},{"name":"2.7.1","sha":"860719db3bf89aeba074c06ebb0a076051d6ab98","kind":"tag","published_at":"2019-04-01T13:03:03.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.7.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.1/manifests"},{"name":"2.7.0","sha":"8588724cf91ddbb53b9c35ed665866556b217323","kind":"tag","published_at":"2018-11-17T12:35:28.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.7.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.7.0/manifests"},{"name":"2.6.0","sha":"106ba84bb04537879d8ce59321a04e0682110b91","kind":"tag","published_at":"2018-09-17T11:01:54.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.6.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.6.0/manifests"},{"name":"2.5.1","sha":"b1ca51bc78d9e974014e70b820c9296db4ecb4f1","kind":"tag","published_at":"2018-08-06T08:46:27.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.5.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.5.1/manifests"},{"name":"2.5.0","sha":"d037ef2e6f35e998e528649195e0369441129a7f","kind":"tag","published_at":"2018-08-03T07:07:51.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.5.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.5.0/manifests"},{"name":"2.4.0","sha":"804d5262a3369623683213b14d6b936066fc7aab","kind":"tag","published_at":"2018-06-04T06:44:48.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.4.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.4.0/manifests"},{"name":"2.3.0","sha":"56a3fee151340212c1b7a92344e4ece07fc15010","kind":"tag","published_at":"2018-04-30T12:35:55.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.3.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.3.0/manifests"},{"name":"2.2.1","sha":"b6381527831c5ebb74759e119a517b7d22d4b23a","kind":"tag","published_at":"2018-03-28T15:50:45.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.2.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.2.1/manifests"},{"name":"2.2.0","sha":"754affa48f749229952e54c8949299c8bf7c5e32","kind":"tag","published_at":"2018-03-05T15:44:07.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.2.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.2.0/manifests"},{"name":"2.1.0","sha":"3ef5b48a028bb66f82b452c98ae515903096641c","kind":"tag","published_at":"2017-12-11T12:56:47.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.1.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.1.0/manifests"},{"name":"2.0.1","sha":"61821cee0e8272430c003cb2393244a836754b1a","kind":"tag","published_at":"2017-10-31T22:58:25.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.0.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.1/manifests"},{"name":"2.0.0","sha":"bd37be4d3b065600c3b76b492535e76e5d413fc1","kind":"tag","published_at":"2017-10-03T15:00:02.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.0.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0/manifests"},{"name":"2.0.0-rc.1","sha":"11e07d3c2b164d06ad35188d83ad70e7501396db","kind":"tag","published_at":"2017-07-12T14:45:08.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.0.0-rc.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.0.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.0.0-rc.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0-rc.1/manifests"},{"name":"2.0.0-pre.1","sha":"0e7abe0b24593f131add272c275406d8ed231805","kind":"tag","published_at":"2017-01-06T14:03:48.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/2.0.0-pre.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/2.0.0-pre.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@2.0.0-pre.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0-pre.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/2.0.0-pre.1/manifests"},{"name":"1.0.2","sha":"45f750db410a4b08c68d142ad0af839f544c5d3d","kind":"commit","published_at":"2015-11-16T16:14:14.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.0.2","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.2/manifests"},{"name":"1.3.0","sha":"14e597baa42a436469f99661ed7994685e269dc2","kind":"commit","published_at":"2015-03-12T16:47:13.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.3.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.3.0/manifests"},{"name":"1.2.0","sha":"0bd62c8920cd7c0f901207320f07229452cc5681","kind":"commit","published_at":"2015-03-06T00:21:32.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.2.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.2.0/manifests"},{"name":"1.1.0","sha":"7caf8cb78ca15aff6a94955fce94458043db6ada","kind":"commit","published_at":"2015-02-16T14:49:33.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.1.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.1.0/manifests"},{"name":"1.0.1","sha":"7d8a571b1e50602d701ca203fbf28036b2cf80f5","kind":"commit","published_at":"2014-11-07T12:14:26.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.0.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.1/manifests"},{"name":"1.0.0","sha":"d544a494af4dbc810fc9c15eaf5cc050cced1501","kind":"commit","published_at":"2014-08-01T09:13:07.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/1.0.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@1.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/1.0.0/manifests"},{"name":"0.6.2","sha":"e2ffefe828b918486e2cd76e44c54ae9b62c616e","kind":"commit","published_at":"2014-06-10T07:32:41.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.6.2","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.2/manifests"},{"name":"0.6.1","sha":"f58340a0044856bb508df03cfe94cf79308380a2","kind":"commit","published_at":"2014-03-27T10:11:04.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.6.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.1/manifests"},{"name":"0.6.0","sha":"a6626f3b4539b07366034b4953ab2df29e3a9d58","kind":"commit","published_at":"2014-03-22T17:58:32.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.6.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.6.0/manifests"},{"name":"0.5.1","sha":"0d4ece08a7cce90a07cf33d4edad29bc324c7d90","kind":"commit","published_at":"2014-02-19T17:59:29.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.5.1","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.5.1/manifests"},{"name":"0.5.0","sha":"2e0fc55f71bfeb543fd2218abed85890ff1e3e82","kind":"commit","published_at":"2014-02-05T15:31:05.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.5.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.5.0/manifests"},{"name":"0.4.0","sha":"63298e8e160031a70efff86a1acde7e7db1fcda6","kind":"commit","published_at":"2013-11-08T14:56:01.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.4.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.4.0/manifests"},{"name":"0.3.0","sha":"34a39ef28ca841fb9233ce9df3ec654eb321c5e5","kind":"commit","published_at":"2013-11-02T11:54:35.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.3.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.3.0/manifests"},{"name":"0.2.0","sha":"85b695c177da63f8b2651c88f8bc43ee511c4509","kind":"commit","published_at":"2013-10-23T14:31:33.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.2.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.2.0/manifests"},{"name":"0.1.0","sha":"2f35af5b0a67f591dde5ae4305a9587988a37c0c","kind":"commit","published_at":"2013-09-04T16:13:39.000Z","download_url":"https://codeload.github.com/ninenines/cowlib/tar.gz/0.1.0","html_url":"https://github.com/ninenines/cowlib/releases/tag/0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/ninenines/cowlib@0.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/tags/0.1.0/manifests"}]},"repo_metadata_updated_at":"2026-10-01T22:30:58.315Z","dependent_packages_count":38,"downloads":105506413,"downloads_period":"total","dependent_repos_count":14134,"rankings":{"downloads":0.346843085618858,"dependent_repos_count":0.08349926135268804,"dependent_packages_count":0.6294559701971867,"stargazers_count":3.577622197957479,"forks_count":1.291027040914638,"docker_downloads_count":0.1477294623932173,"average":1.012696169739011},"purl":"pkg:hex/cowlib","advisories":[{"uuid":"EEF-CVE-2026-43971","url":"https://cna.erlef.org/cves/CVE-2026-43971.html","title":"Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1","description":"## Summary\n\nImproper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in `cow_link:link/1`.\n\n`cow_link:do_link/1` in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized `Link:` header value without escaping or token-grammar validation. A `\u003e` byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A `\"` or `\\` in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, `=`, and `\"` — in an attribute key is emitted verbatim. Because browsers act on `Link:` directives such as `rel=\"preconnect\"`, `rel=\"preload\"`, and `rel=\"prerender\"`, an attacker who can influence these fields in an application that round-trips parsed Link headers through `cow_link:link/1` can force victim browsers to make out-of-band connections to attacker-controlled origins.\n\nThis issue affects cowlib: from 2.9.0 before 2.20.0.\n\n## Workarounds\n\nSanitize values before passing them to `cow_link:link/1`: reject or strip any target value containing `\u003e`, any rel value containing `\"` or `\\`, and any attribute key containing characters outside the HTTP token grammar. Alternatively, ensure all Link entry fields are derived exclusively from trusted, application-controlled values rather than untrusted input.\n\n## Configurations\n\nThe application must pass values that originate from, or can be influenced by, untrusted input into `cow_link:link/1` — specifically the target URI, rel value, or attribute keys. Applications that construct Link entries exclusively from trusted, application-controlled values are not affected.","origin":"ERLEF","severity":"MEDIUM","published_at":"2026-08-18T09:01:53.199Z","withdrawn_at":null,"classification":null,"cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-43971.html","https://github.com/ninenines/cowlib/commit/485d58dfa91b91d98135dc95e5615f421715dae5","https://github.com/ninenines/cowlib/commit/89da27ee4c241f5d649ba7d9b7f2188918af6cea","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-43971","CVE-2026-43971"],"repository_url":"https://github.com/ninenines/cowlib","blast_radius":26.14667004796583,"created_at":"2026-08-18T09:19:19.563Z","updated_at":"2026-09-16T20:24:09.724Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43971","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-43971","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.20.0","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.20.0"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.16.1","2.17.0","2.17.1","2.18.0","2.19.0"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.20.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43971/related_packages","related_advisories":[]},{"uuid":"EEF-CVE-2026-59248","url":"https://cna.erlef.org/cves/CVE-2026-59248.html","title":"Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS","description":"## Summary\n\nAllocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service.\n\nThe HPACK and QPACK prefixed-integer decoder cow\\_hpack\\_common:dec\\_big\\_int/3 in src/cow\\_hpack\\_common.hrl (invoked from cow\\_hpack:decode/2 in src/cow\\_hpack.erl and from cow\\_qpack:decode\\_field\\_section/3 in src/cow\\_qpack.erl) reads continuation octets until it sees one whose high bit is clear, evaluating Int + (Value bsl M) at each step with the shift M growing by seven per octet. No limit is enforced on the number of continuation octets, on the resulting bit width, or on the value; the decoder consumes whatever encoded length the peer supplies.\n\nBecause Erlang integers are immutable, each intermediate Value bsl M and each accumulator update allocates a fresh bignum whose digit width grows linearly with the number of octets processed so far. Summed across the whole decode, the transient bignum digit materialization is on the order of the square of the encoded length. A single maximal HPACK indexed representation carried inside one HTTP/2 HEADERS plus one CONTINUATION frame at Cowboy's default max\\_frame\\_size\\_received can force hundreds of megabytes of transient allocation and garbage-collection churn before the resulting header-table index is rejected as invalid. Repeated or concurrent connections multiply the pressure and can drive the Erlang VM to memory exhaustion.\n\nCowlib is the HTTP parser used by Cowboy, RabbitMQ's management plugin, and other Erlang and Elixir HTTP/2 and HTTP/3 servers and clients, so any exposed endpoint that accepts HPACK or QPACK from an untrusted peer is reachable.\n\nThis issue affects cowlib: from 2.0.0 before 2.19.0.","origin":"ERLEF","severity":"HIGH","published_at":"2026-07-28T09:54:19.579Z","withdrawn_at":null,"classification":null,"cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-59248.html","https://github.com/ninenines/cowlib/commit/f582430498072a0c65ad338030321576dc13a343","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-59248","CVE-2026-59248"],"repository_url":"https://github.com/ninenines/cowlib","blast_radius":36.107306256714715,"created_at":"2026-07-28T10:31:06.086Z","updated_at":"2026-07-30T18:22:03.583Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-59248","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-59248","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.19.0","vulnerable_version_range":"\u003e= 2.0.0-pre.1, \u003c 2.19.0"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.16.1","2.17.0","2.17.1","2.18.0"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.19.0","2.20.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-59248/related_packages","related_advisories":[]},{"uuid":"EEF-CVE-2026-43966","url":"https://cna.erlef.org/cves/CVE-2026-43966.html","title":"HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2","description":"## Summary\n\nImproper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values.\n\ncow\\_http\\_struct\\_hd:escape\\_string/2 in cowlib only escapes \\\\ and \", passing all other bytes through verbatim. This creates an encoder/decoder asymmetry: the matching parser accepts only printable ASCII (0x20–0x7E, excluding \" and \\\\), but the encoder emits any byte including CR and LF. An application that builds a structured HTTP header via cow\\_http\\_struct\\_hd:item/1 (or a higher-level wrapper such as cow\\_http\\_hd:wt\\_protocol/1) from attacker-controlled input can have \\\\r\\\\n injected into the serialized header value. Once on the wire, the injected CRLF terminates the current header and any following bytes are interpreted as a new header, enabling HTTP response splitting.\n\nThis issue affects cowlib from 2.9.0.\n\n## Workarounds\n\nValidate all values passed into structured-fields header builders (directly via cow\\_http\\_struct\\_hd:item/1 or indirectly via higher-level wrappers) before calling the encoder. Reject any value that is not from a trusted, application-controlled source or that contains CR (\\\\r) or LF (\\\\n) bytes.\n\nApplications using cowboy 2.16.0 or later are protected on the server side by the invalid\\_response\\_headers option (defaults to error\\_terminate), which rejects any outgoing response header value containing CR or LF before it reaches the wire. Applications using gun 2.4.0 or later are protected on the client side by the invalid\\_request\\_headers request option (defaults to raise), which raises an exception when an outgoing request header value contains CR or LF.\n\n## Configurations\n\nThe application must pass attacker-controlled data as a string value into cow\\_http\\_struct\\_hd:item/1 (or a wrapper that delegates to it). Applications that construct structured-fields header values exclusively from trusted, application-controlled values are not affected.","origin":"ERLEF","severity":"MEDIUM","published_at":"2026-06-08T16:34:33.364Z","withdrawn_at":null,"classification":null,"cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-43966.html","https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef","https://github.com/ninenines/gun/commit/4f35609eb37109b106a863fc9ba83d7ee64e3e42","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-43966","CVE-2026-43966"],"repository_url":"https://github.com/ninenines/cowboy","blast_radius":26.14667004796583,"created_at":"2026-06-08T17:18:00.265Z","updated_at":"2026-09-09T03:30:04.772Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43966","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-43966","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.9.0"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.16.1","2.17.0","2.17.1","2.18.0","2.19.0","2.20.0"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43966/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS13NGY3LTRjeHItcnYzY84ABYRv","source_kind":"github","url":"https://github.com/advisories/GHSA-w4f7-4cxr-rv3c"}]},{"uuid":"GSA_kwCzR0hTQS04NGYyLXJwODYtMjM1cM4ABW1C","url":"https://github.com/advisories/GHSA-84f2-rp86-235p","title":"cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","description":"Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion.\n\ncow_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes directly to zlib:inflate/2 with no output size bound. The SPDY header compression dictionary (?ZDICT) is public, and zlib compresses long runs of repeated bytes at roughly 1024:1, so a few kilobytes of SPDY frame payload can decompress to gigabytes on the BEAM heap, OOM-killing the node. A single unauthenticated SPDY frame is sufficient to trigger the condition. The parsers for syn_stream, syn_reply, and headers frame types are all affected via cow_spdy:parse_headers/2.\n\nThis issue affects cowlib from 0.1.0 before 2.16.1.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-13T21:32:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-43970","https://github.com/ninenines/cowlib/commit/16aad3fb9f81f5cda4d1706ff0c54237c619c282","https://cna.erlef.org/cves/CVE-2026-43970.html","https://osv.dev/vulnerability/EEF-CVE-2026-43970","https://github.com/advisories/GHSA-84f2-rp86-235p"],"source_kind":"github","identifiers":["GHSA-84f2-rp86-235p","CVE-2026-43970"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T21:00:18.819Z","updated_at":"2026-09-30T09:03:13.411Z","epss_percentage":0.00637,"epss_percentile":0.48502,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NGYyLXJwODYtMjM1cM4ABW1C","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NGYyLXJwODYtMjM1cM4ABW1C","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 0.1.0, \u003c 2.16.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NGYyLXJwODYtMjM1cM4ABW1C/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-43970","source_kind":"erlef","url":"https://cna.erlef.org/cves/CVE-2026-43970.html"}]},{"uuid":"EEF-CVE-2026-43970","url":"https://cna.erlef.org/cves/CVE-2026-43970.html","title":"Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","description":"## Summary\n\nImproper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion.\n\ncow\\_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes directly to zlib:inflate/2 with no output size bound. The SPDY header compression dictionary (?ZDICT) is public, and zlib compresses long runs of repeated bytes at roughly 1024:1, so a few kilobytes of SPDY frame payload can decompress to gigabytes on the BEAM heap, OOM-killing the node. A single unauthenticated SPDY frame is sufficient to trigger the condition. The parsers for syn\\_stream, syn\\_reply, and headers frame types are all affected via cow\\_spdy:parse\\_headers/2.\n\nThis issue affects cowlib from 0.1.0 before 2.16.1.\n\n## Configurations\n\nThe application must use cow\\_spdy:parse/2 to parse SPDY frames from an untrusted peer. cowboy itself does not use cow\\_spdy; only direct callers of the cow\\_spdy API are affected.\n\n## Solutions\n\nUpgrade to cowlib 2.16.1 or later, in which the cow\\_spdy module has been removed entirely. No patched version of cow\\_spdy will be provided. Migrate away from SPDY, which has been deprecated since 2015 in favour of HTTP/2.","origin":"ERLEF","severity":"HIGH","published_at":"2026-05-13T18:43:11.640Z","withdrawn_at":null,"classification":null,"cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-43970.html","https://github.com/ninenines/cowlib/commit/16aad3fb9f81f5cda4d1706ff0c54237c619c282","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-43970","CVE-2026-43970"],"repository_url":"https://github.com/ninenines/cowlib","blast_radius":34.03217371322537,"created_at":"2026-05-13T19:19:58.100Z","updated_at":"2026-09-08T03:30:06.054Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43970","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-43970","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 0.1.0, \u003c 2.16.1"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0"],"unaffected_versions":["2.16.1","2.17.0","2.17.1","2.18.0","2.19.0","2.20.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43970/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS04NGYyLXJwODYtMjM1cM4ABW1C","source_kind":"github","url":"https://github.com/advisories/GHSA-84f2-rp86-235p"}]},{"uuid":"GSA_kwCzR0hTQS0zMnA5LTU3Y3ItNHg2Nc4ABWml","url":"https://github.com/advisories/GHSA-32p9-57cr-4x65","title":" cowlib cow_http_te module: Uncontrolled Resource Consumption vulnerability allows Excessive Allocation","description":"Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation.\n\nThe chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len * 16 + digit), so parsing N hex digits requires O(N²) CPU work and O(N) memory. Additionally, when input is drip-fed, the parser discards the accumulated length on each partial read and restarts from zero on resumption, raising the cost to O(N³). An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a very long chunk-size hex string to cause denial of service through CPU exhaustion and memory amplification.\n\nThis vulnerability is associated with program file src/cow_http_te.erl and program routines cow_http_te:stream_chunked/2, cow_http_te:chunked_len/4.\n\nThis issue affects cowlib: from 0.6.0 before 2.16.1.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-11T21:31:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-7790","https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369","https://cna.erlef.org/cves/CVE-2026-7790.html","https://osv.dev/vulnerability/EEF-CVE-2026-7790","https://github.com/ninenines/cowlib/releases/tag/2.16.1","https://github.com/advisories/GHSA-32p9-57cr-4x65"],"source_kind":"github","identifiers":["GHSA-32p9-57cr-4x65","CVE-2026-7790"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-18T17:00:16.637Z","updated_at":"2026-09-28T20:03:18.799Z","epss_percentage":0.00793,"epss_percentile":0.54504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zMnA5LTU3Y3ItNHg2Nc4ABWml","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zMnA5LTU3Y3ItNHg2Nc4ABWml","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 0.6.0, \u003c 2.16.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zMnA5LTU3Y3ItNHg2Nc4ABWml/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-7790","source_kind":"erlef","url":"https://cna.erlef.org/cves/CVE-2026-7790.html"}]},{"uuid":"GSA_kwCzR0hTQS1odjIzLTRxcDctOGM4cs4ABWm0","url":"https://github.com/advisories/GHSA-hv23-4qp7-8c8r","title":"ninenines cowlib: Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability allows SSE event splitting and injection via unvalidated field values","description":"Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values.\n\ncow_sse:event/1 in cowlib guards the id and event fields against \\n but not against bare \\r, and the internal prefix_lines/2 function used for data and comment fields splits only on \\n. Because the SSE specification requires decoders to treat \\r\\n, \\r, and \\n as equivalent line terminators, an attacker who controls any of these fields can inject additional SSE lines and forge a complete event with an arbitrary event type and data payload on the receiving end. In typical deployments where browser EventSource clients or other SSE consumers dispatch on event.type and render event.data, this enables event splitting, client-side logic manipulation, and stored-XSS-equivalent behaviour when event data is inserted into the DOM.\n\nThis issue affects cowlib from 2.6.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-11T21:31:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-43968","https://github.com/ninenines/cowlib/commit/6165fc40efa159ba1cceee7e7981e790acba5d9c","https://cna.erlef.org/cves/CVE-2026-43968.html","https://osv.dev/vulnerability/EEF-CVE-2026-43968","https://github.com/ninenines/cowlib/releases/tag/2.16.1","https://github.com/advisories/GHSA-hv23-4qp7-8c8r"],"source_kind":"github","identifiers":["GHSA-hv23-4qp7-8c8r","CVE-2026-43968"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-18T17:00:16.637Z","updated_at":"2026-09-30T09:03:20.864Z","epss_percentage":0.00461,"epss_percentile":0.375,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1odjIzLTRxcDctOGM4cs4ABWm0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1odjIzLTRxcDctOGM4cs4ABWm0","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 2.6.0, \u003c 2.16.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1odjIzLTRxcDctOGM4cs4ABWm0/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-43968","source_kind":"erlef","url":"https://cna.erlef.org/cves/CVE-2026-43968.html"}]},{"uuid":"GSA_kwCzR0hTQS1nMndtLTczNXEtM2Y1Ns4ABWms","url":"https://github.com/advisories/GHSA-g2wm-735q-3f56","title":"cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1","description":"Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.\n\ncow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject ;, ,, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting \"; admin=1\" to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (parse_cookie_name/1, parse_cookie_value/1) and setcookie/3 already validate and reject these characters; the encoder alone is missing the check.\n\nThis issue affects cowlib from 2.9.0.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-05-11T21:31:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.1,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-43969","https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144","https://cna.erlef.org/cves/CVE-2026-43969.html","https://osv.dev/vulnerability/EEF-CVE-2026-43969","https://github.com/advisories/GHSA-g2wm-735q-3f56"],"source_kind":"github","identifiers":["GHSA-g2wm-735q-3f56","CVE-2026-43969"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-18T18:00:17.572Z","updated_at":"2026-09-25T12:03:37.033Z","epss_percentage":0.00209,"epss_percentile":0.09887,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nMndtLTczNXEtM2Y1Ns4ABWms","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nMndtLTczNXEtM2Y1Ns4ABWms","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.16.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nMndtLTczNXEtM2Y1Ns4ABWms/related_packages","related_advisories":[{"uuid":"EEF-CVE-2026-43969","source_kind":"erlef","url":"https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144"}]},{"uuid":"EEF-CVE-2026-43968","url":"https://cna.erlef.org/cves/CVE-2026-43968.html","title":"CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1","description":"## Summary\n\nImproper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values.\n\ncow\\_sse:event/1 in cowlib guards the id and event fields against \\\\n but not against bare \\\\r, and the internal prefix\\_lines/2 function used for data and comment fields splits only on \\\\n. Because the SSE specification requires decoders to treat \\\\r\\\\n, \\\\r, and \\\\n as equivalent line terminators, an attacker who controls any of these fields can inject additional SSE lines and forge a complete event with an arbitrary event type and data payload on the receiving end. In typical deployments where browser EventSource clients or other SSE consumers dispatch on event.type and render event.data, this enables event splitting, client-side logic manipulation, and stored-XSS-equivalent behaviour when event data is inserted into the DOM.\n\nThis issue affects cowlib from 2.6.0 before 2.16.1.\n\n## Workarounds\n\nSanitize user-controlled values before passing them to cow\\_sse:event/1: reject or strip any value containing \\\\r or \\\\n characters in the id, event, data, and comment fields. Alternatively, ensure that all SSE field values are derived exclusively from trusted, application-controlled data rather than user input.\n\n## Configurations\n\nThe application must pass user-controlled data as the id, event, data, or comment field to cow\\_sse:event/1 (or a higher-level wrapper such as cowboy\\_req:stream\\_events/3). Applications that construct SSE events exclusively from trusted, application-controlled values are not affected.","origin":"ERLEF","severity":"MEDIUM","published_at":"2026-05-11T18:06:42.881Z","withdrawn_at":null,"classification":null,"cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-43968.html","https://github.com/ninenines/cowlib/commit/6165fc40efa159ba1cceee7e7981e790acba5d9c","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-43968","CVE-2026-43968"],"repository_url":"https://github.com/ninenines/cowlib","blast_radius":26.14667004796583,"created_at":"2026-05-11T19:17:16.552Z","updated_at":"2026-10-02T20:27:35.329Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43968","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-43968","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 2.6.0, \u003c 2.16.1"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.16.1","2.17.0","2.17.1","2.18.0","2.19.0","2.20.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43968/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS1odjIzLTRxcDctOGM4cs4ABWm0","source_kind":"github","url":"https://github.com/advisories/GHSA-hv23-4qp7-8c8r"}]},{"uuid":"EEF-CVE-2026-7790","url":"https://cna.erlef.org/cves/CVE-2026-7790.html","title":"Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS","description":"## Summary\n\nUncontrolled Resource Consumption vulnerability in ninenines cowlib (cow\\_http\\_te module) allows Excessive Allocation.\n\nThe chunked transfer-encoding parser in cow\\_http\\_te accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len \\* 16 + digit), so parsing N hex digits requires O(N²) CPU work and O(N) memory. Additionally, when input is drip-fed, the parser discards the accumulated length on each partial read and restarts from zero on resumption, raising the cost to O(N³). An unauthenticated remote attacker can exploit this by sending an HTTP/1.1 request with Transfer-Encoding: chunked and a very long chunk-size hex string to cause denial of service through CPU exhaustion and memory amplification.\n\nThis vulnerability is associated with program file src/cow\\_http\\_te.erl and program routines cow\\_http\\_te:stream\\_chunked/2, cow\\_http\\_te:chunked\\_len/4.\n\nThis issue affects cowlib: from 0.6.0 before 2.16.1.\n\n## Workarounds\n\nIn Cowboy, setting initial\\_stream\\_flow\\_size to a much lower value limits the amount of chunked body data that cowlib will parse in a single read, reducing the window of data an attacker can use to trigger the quadratic work. This does not fully eliminate the vulnerability but can significantly reduce its impact for some applications.","origin":"ERLEF","severity":"HIGH","published_at":"2026-05-11T18:06:41.490Z","withdrawn_at":null,"classification":null,"cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://cna.erlef.org/cves/CVE-2026-7790.html","https://github.com/ninenines/cowlib/commit/a4b8039ce8c93ab00867ef6b7e888822c09f4369","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-7790","CVE-2026-7790"],"repository_url":"https://github.com/ninenines/cowlib","blast_radius":36.107306256714715,"created_at":"2026-05-11T19:17:16.674Z","updated_at":"2026-10-02T20:27:43.175Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-7790","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-7790","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":"2.16.1","vulnerable_version_range":"\u003e= 0.6.0, \u003c 2.16.1"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0"],"unaffected_versions":["2.16.1","2.17.0","2.17.1","2.18.0","2.19.0","2.20.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-7790/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS0zMnA5LTU3Y3ItNHg2Nc4ABWml","source_kind":"github","url":"https://github.com/advisories/GHSA-32p9-57cr-4x65"}]},{"uuid":"EEF-CVE-2026-43969","url":"https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144","title":"Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1","description":"## Summary\n\nImproper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields.\n\n`cow_cookie:cookie/1` in cowlib builds a client-side `Cookie:` request header from a list of name-value pairs without validating either field. An attacker who controls the cookie names or values passed to this function can inject `;`, `,`, CR, LF, or TAB characters into the serialized header. This enables two classes of attack: cookie smuggling within a single header (e.g. injecting `; admin=1` to introduce a phantom cookie that the receiving server treats as authentic) and HTTP request header splitting (injecting CRLF to append arbitrary headers or smuggle a complete second request against a shared upstream proxy). The decoder side (`parse_cookie_name/1`, `parse_cookie_value/1`) and `setcookie/3` already validate and reject these characters; the encoder alone is missing the check.\n\nThis issue affects cowlib: from 2.9.0 onward.\n\n## Workarounds\n\nValidate inputs into `cow_cookie:cookie/1` to only include valid cookie name and value characters as defined in RFC 6265 Section 4.1.1 before passing them to the function.\n\n## Configurations\n\nThe application must pass attacker-controlled bytes as cookie names or values to `cow_cookie:cookie/1`. Applications that construct cookie lists exclusively from trusted, application-controlled values are not affected.","origin":"ERLEF","severity":"LOW","published_at":"2026-05-11T18:06:40.667Z","withdrawn_at":null,"classification":null,"cvss_score":2.1,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://github.com/erlef/cowlib/commit/177953dd51540da11090666c1f007214127a1144","https://cna.erlef.org/cves/CVE-2026-43969.html","https://hex.pm/packages/cowlib"],"source_kind":"erlef","identifiers":["EEF-CVE-2026-43969","CVE-2026-43969"],"repository_url":"https://github.com/erlef/cowlib","blast_radius":8.715556682655277,"created_at":"2026-05-11T19:17:16.629Z","updated_at":"2026-09-09T14:30:01.210Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43969","html_url":"https://advisories.ecosyste.ms/advisories/EEF-CVE-2026-43969","packages":[{"ecosystem":"hex","package_name":"cowlib","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003e= 2.9.0"}],"purl":null,"statistics":{"dependent_packages_count":38,"dependent_repos_count":14134,"downloads":105433264,"downloads_period":"total"},"affected_versions":["2.9.0","2.9.1","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.0","2.16.0","2.16.1","2.17.0","2.17.1","2.18.0","2.19.0","2.20.0"],"unaffected_versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/EEF-CVE-2026-43969/related_packages","related_advisories":[{"uuid":"GSA_kwCzR0hTQS1nMndtLTczNXEtM2Y1Ns4ABWms","source_kind":"github","url":"https://github.com/advisories/GHSA-g2wm-735q-3f56"}]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/hex/cowlib","docker_dependents_count":61,"docker_downloads_count":577125,"usage_url":"https://repos.ecosyste.ms/usage/hex/cowlib","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/hex/cowlib/dependencies","status":null,"funding_links":["https://github.com/sponsors/essen","https://ninenines.eu/services/#_sponsoring"],"critical":true,"issue_metadata":{"last_synced_at":"2026-09-30T22:23:03.066Z","issues_count":54,"pull_requests_count":97,"avg_time_to_close_issue":20522695.023255814,"avg_time_to_close_pull_request":19169604.871794872,"issues_closed_count":43,"pull_requests_closed_count":78,"pull_request_authors_count":52,"issue_authors_count":37,"avg_comments_per_issue":2.685185185185185,"avg_comments_per_pull_request":2.9072164948453607,"merged_pull_requests_count":13,"bot_issues_count":0,"bot_pull_requests_count":0,"past_year_issues_count":5,"past_year_pull_requests_count":28,"past_year_avg_time_to_close_issue":6432092.0,"past_year_avg_time_to_close_pull_request":524598.3333333334,"past_year_issues_closed_count":4,"past_year_pull_requests_closed_count":12,"past_year_pull_request_authors_count":14,"past_year_issue_authors_count":5,"past_year_avg_comments_per_issue":2.8,"past_year_avg_comments_per_pull_request":1.7142857142857142,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":0,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/ninenines%2Fcowlib/issues","maintainers":[{"login":"essen","count":29,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/essen"},{"login":"grok-99s","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/grok-99s"}],"active_maintainers":[{"login":"grok-99s","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/grok-99s"},{"login":"essen","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/essen"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/packages/cowlib/codemeta","maintainers":[{"uuid":"gazler","login":"gazler","name":null,"email":"gazler@gmail.com","url":null,"packages_count":23,"html_url":"https://hex.pm/users/gazler","role":null,"created_at":"2022-11-08T09:40:38.327Z","updated_at":"2022-11-08T09:40:38.327Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/gazler/packages"},{"uuid":"ericmj","login":"ericmj","name":null,"email":"eric.meadows.jonsson@gmail.com","url":null,"packages_count":21,"html_url":"https://hex.pm/users/ericmj","role":null,"created_at":"2022-11-08T09:40:38.312Z","updated_at":"2022-11-08T09:40:38.312Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/ericmj/packages"},{"uuid":"essen","login":"essen","name":null,"email":"essen@ninenines.eu","url":null,"packages_count":4,"html_url":"https://hex.pm/users/essen","role":null,"created_at":"2022-11-08T09:40:38.342Z","updated_at":"2022-11-08T09:40:38.342Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/hex.pm/maintainers/essen/packages"}]}