Summary
mix hex.audit reports three encoder advisories against the latest available Cowlib release, 2.19.0:
EEF-CVE-2026-43966 (medium): structured HTTP header response splitting when attacker-controlled bytes reach cow_http_struct_hd:escape_string/2.
EEF-CVE-2026-43969 (low): request header/cookie injection when attacker-controlled names or values reach cow_cookie:cookie/1.
EEF-CVE-2026-43971 (medium): Link header directive smuggling when attacker-controlled target, relation, or attribute-key values reach cow_link:link/1.
Current assessment
Last reviewed: 2026-08-25.
- LLMProxy resolves Cowboy 2.18.0 and Cowlib 2.19.0. Cowlib 2.19.0 remains the latest Hex release, so no patched registry version is available.
- Cowboy 2.16.0 and later reject CR/LF response-header values by default through
invalid_response_headers: error_terminate, providing the documented server-side mitigation for EEF-CVE-2026-43966.
- A source scan of LLMProxy
master and its resolved dependencies found no calls that build request Cookie headers through cow_cookie:cookie/1.
- The same scan found no LLMProxy calls that build Link headers through
cow_link:link/1, and no application-controlled use of the affected structured-header string builders.
- Cowlib commit
89da27e fixes EEF-CVE-2026-43971 upstream, but the fix has not yet been included in a Hex release.
Based on current call paths, no directly exploitable LLMProxy path is known. The dependency audit remains red until Cowlib publishes a compatible fixed release or the advisory metadata is corrected.
Follow-up
- Keep this issue open and monitor Cowlib/Hex advisory metadata for a fixed release or corrected affected range.
- Upgrade when a patched Cowboy-compatible Cowlib release becomes available.
- Re-run
mix hex.audit before each package release.
- Reassess immediately if LLMProxy begins constructing structured headers, Link headers, or Cookie request headers from caller-controlled values.
Summary
mix hex.auditreports three encoder advisories against the latest available Cowlib release, 2.19.0:EEF-CVE-2026-43966(medium): structured HTTP header response splitting when attacker-controlled bytes reachcow_http_struct_hd:escape_string/2.EEF-CVE-2026-43969(low): request header/cookie injection when attacker-controlled names or values reachcow_cookie:cookie/1.EEF-CVE-2026-43971(medium): Link header directive smuggling when attacker-controlled target, relation, or attribute-key values reachcow_link:link/1.Current assessment
Last reviewed: 2026-08-25.
invalid_response_headers: error_terminate, providing the documented server-side mitigation forEEF-CVE-2026-43966.masterand its resolved dependencies found no calls that build request Cookie headers throughcow_cookie:cookie/1.cow_link:link/1, and no application-controlled use of the affected structured-header string builders.89da27efixesEEF-CVE-2026-43971upstream, but the fix has not yet been included in a Hex release.Based on current call paths, no directly exploitable LLMProxy path is known. The dependency audit remains red until Cowlib publishes a compatible fixed release or the advisory metadata is corrected.
Follow-up
mix hex.auditbefore each package release.