Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43971

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins. This issue affects cowlib: from 2.9.0 onward.

A flaw was found in ninenines cowlib. This vulnerability, due to improper encoding or escaping of output, allows an attacker to perform Link header directive smuggling. By manipulating the target URI, 'rel' value, or attribute keys in applications that process Link headers through cowlib, a remote attacker can inject malicious directives. This can force victim browsers to establish out-of-band connections to attacker-controlled servers, potentially leading to information disclosure or bypassing security controls.

Отчет

A flaw was found in cowlib, an Erlang library for HTTP parsing and manipulation. Due to improper encoding of output in the cow_link:link/1 function, an attacker can perform Link header directive smuggling by injecting special characters in the target URI, rel value, or attribute keys. Applications that process Link headers through cowlib and pass untrusted input to cow_link:link/1 may force victim browsers to establish out-of-band connections to attacker-controlled servers, potentially leading to information disclosure or bypassing security controls. Red Hat products that bundle cowlib are only affected if they call cow_link:link/1 with untrusted input; actual exploitability in RabbitMQ Server has not been verified.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverFix deferred
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.5-1.1.hum1FixedRHSA-2026:6621009.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-838
https://bugzilla.redhat.com/show_bug.cgi?id=2517738cowlib: cowlib: Link header smuggling allows out-of-band connections to attacker-controlled origins

4.3 Medium

CVSS3

Связанные уязвимости

ubuntu
6 дней назад

(Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)

nvd
около 1 месяца назад

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins. This issue affects cowlib: from 2.

msrc
29 дней назад

Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1

debian
около 1 месяца назад

Improper Encoding or Escaping of Output vulnerability in ninenines cow ...

github
около 1 месяца назад

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins. This issue affects cowlib: from...

4.3 Medium

CVSS3