The number and severity of CVEs published that impact products developed by Ninenines over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43970HIGH Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion.
cow_spdy: | May 13, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-7790HIGH Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation.
The chunked transfer-encoding parser in cow_http_te accepts a | May 11, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-43968MEDIUM Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values.
cow_sse:event | May 11, 2026 | 4.0 | 21 | NO | NO |
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and va | May 11, 2026 | 3.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ninenines.
Media articles that mention a CVE ID that affects a product developed by Ninenines — matched by CVE ID, not by vendor name.