Support library for manipulating Web protocols.
cowlib is deprecated — find an alternative
Update to >= a4b8039ce8c93ab00867ef6b7e888822c09f4369 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2026-43966 | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 | — |
| medium | CVE-2026-43968 | CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 | 6165fc40efa159ba1cceee7e7981e790acba5d9c |
| low | CVE-2026-43969 | Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 | — |
| high | CVE-2026-43970 | Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame | 16aad3fb9f81f5cda4d1706ff0c54237c619c282 |
| medium | CVE-2026-43971 | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 | 89da27ee4c241f5d649ba7d9b7f2188918af6cea |
| high | CVE-2026-59248 | Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS | f582430498072a0c65ad338030321576dc13a343 |
| high | CVE-2026-7790 | Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS | a4b8039ce8c93ab00867ef6b7e888822c09f4369 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/hex/cowlibFirst published · 2014-08-01T16:06:22.000000Z
Last updated · 2026-09-08T14:48:09.329731Z