Skip to content

Track unresolved Cowlib encoder advisories #1

Description

@dannote

Summary

mix hex.audit reports three encoder advisories against the latest available Cowlib release, 2.19.0:

  • EEF-CVE-2026-43966 (medium): structured HTTP header response splitting when attacker-controlled bytes reach cow_http_struct_hd:escape_string/2.
  • EEF-CVE-2026-43969 (low): request header/cookie injection when attacker-controlled names or values reach cow_cookie:cookie/1.
  • EEF-CVE-2026-43971 (medium): Link header directive smuggling when attacker-controlled target, relation, or attribute-key values reach cow_link:link/1.

Current assessment

Last reviewed: 2026-08-25.

  • LLMProxy resolves Cowboy 2.18.0 and Cowlib 2.19.0. Cowlib 2.19.0 remains the latest Hex release, so no patched registry version is available.
  • Cowboy 2.16.0 and later reject CR/LF response-header values by default through invalid_response_headers: error_terminate, providing the documented server-side mitigation for EEF-CVE-2026-43966.
  • A source scan of LLMProxy master and its resolved dependencies found no calls that build request Cookie headers through cow_cookie:cookie/1.
  • The same scan found no LLMProxy calls that build Link headers through cow_link:link/1, and no application-controlled use of the affected structured-header string builders.
  • Cowlib commit 89da27e fixes EEF-CVE-2026-43971 upstream, but the fix has not yet been included in a Hex release.

Based on current call paths, no directly exploitable LLMProxy path is known. The dependency audit remains red until Cowlib publishes a compatible fixed release or the advisory metadata is corrected.

Follow-up

  • Keep this issue open and monitor Cowlib/Hex advisory metadata for a fixed release or corrected affected range.
  • Upgrade when a patched Cowboy-compatible Cowlib release becomes available.
  • Re-run mix hex.audit before each package release.
  • Reassess immediately if LLMProxy begins constructing structured headers, Link headers, or Cookie request headers from caller-controlled values.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions