{"package":"cowlib","ecosystem":"hex","latest_version":"2.20.0","description":"Support library for manipulating Web protocols.","license":"ISC","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://ninenines.eu/docs/en/cowlib/2.20/manual/","repository":"https://github.com/ninenines/cowlib","downloads_weekly":396221,"health":{"score":35,"risk":"critical","breakdown":{"maintenance":25,"popularity":14,"security":4,"maturity":15,"community":7},"deprecated":true,"max_score":100},"vulnerabilities":{"count":7,"critical":0,"high":3,"medium":3,"low":1,"details":[{"vuln_id":"CVE-2026-43966","severity":"medium","summary":"HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2","affected_versions":">=2.9.0|>=a8b793db3d6ffe91d62f81baf41b1dab4cd78fb6|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.16.1|=2.17.0|=2.17.1|=2.18.0|=2.19.0|=2.20.0|=2.9.0|=2.9.1|=2.20.0|=2.19.0|=2.18.0|=2.17.1|=2.17.0|=2.16.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0","fixed_version":null,"source":"osv","published_at":"2026-06-08T16:34:33.364Z"},{"vuln_id":"CVE-2026-43968","severity":"medium","summary":"CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1","affected_versions":">=2.6.0,<2.16.1|>=93b2b897cde238506c803faad4d1602d79dba7c9,<6165fc40efa159ba1cceee7e7981e790acba5d9c|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.7.3|=2.8.0|=2.9.0|=2.9.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0|=2.8.0|=2.7.3|=2.7.2|=2.7.1|=2.7.0|=2.6.0|=2.5.1|=2.5.0","fixed_version":"6165fc40efa159ba1cceee7e7981e790acba5d9c","source":"osv","published_at":"2026-05-11T18:06:42.881Z"},{"vuln_id":"CVE-2026-43969","severity":"low","summary":"Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1","affected_versions":">=2.9.0|>=f017f8a0ecbffd5033d9ab49bf180186f7a523a7|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.16.1|=2.17.0|=2.17.1|=2.18.0|=2.19.0|=2.20.0|=2.9.0|=2.9.1|=2.20.0|=2.19.0|=2.18.0|=2.17.1|=2.17.0|=2.16.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0","fixed_version":null,"source":"osv","published_at":"2026-05-11T18:06:40.667Z"},{"vuln_id":"CVE-2026-43970","severity":"high","summary":"Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","affected_versions":">=0.1.0,<2.16.1|>=fad5c0049df278cc498b6cdb519b09e845a070a8,<16aad3fb9f81f5cda4d1706ff0c54237c619c282|=1.0.0|=1.0.1|=1.0.2|=1.1.0|=1.2.0|=1.3.0|=2.0.0|=2.0.1|=2.1.0|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.2.0|=2.2.1|=2.3.0|=2.4.0|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.7.3|=2.8.0|=2.9.0|=2.9.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0|=2.8.0|=2.7.3|=2.7.2|=2.7.1|=2.7.0|=2.6.0|=2.5.1|=2.5.0|=2.4.0|=2.3.0|=2.2.1|=2.2.0|=2.1.0|=2.0.1|=2.0.0|=2.0.0-rc.1|=2.0.0-pre.1|=1.0.1|=1.3.0|=1.2.0|=1.1.0|=1.0.0|=0.6.2|=0.6.1|=0.6.0|=0.5.1|=0.5.0|=0.4.0|=0.3.0|=0.2.0|=0.1.0","fixed_version":"16aad3fb9f81f5cda4d1706ff0c54237c619c282","source":"osv","published_at":"2026-05-13T18:43:11.640Z"},{"vuln_id":"CVE-2026-43971","severity":"medium","summary":"Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1","affected_versions":">=2.9.0,<2.20.0|>=485d58dfa91b91d98135dc95e5615f421715dae5,<89da27ee4c241f5d649ba7d9b7f2188918af6cea|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.16.1|=2.17.0|=2.17.1|=2.18.0|=2.19.0|=2.9.0|=2.9.1|=2.19.0|=2.18.0|=2.17.1|=2.17.0|=2.16.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0","fixed_version":"89da27ee4c241f5d649ba7d9b7f2188918af6cea","source":"osv","published_at":"2026-08-18T09:01:53.199Z"},{"vuln_id":"CVE-2026-59248","severity":"high","summary":"Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS","affected_versions":">=2.0.0-pre.1,<2.19.0|>=5ddecbc121f812aec53d9df91829448d8e94e44c,<f582430498072a0c65ad338030321576dc13a343|=2.0.0|=2.0.1|=2.1.0|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.16.1|=2.17.0|=2.17.1|=2.18.0|=2.2.0|=2.2.1|=2.3.0|=2.4.0|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.7.3|=2.8.0|=2.9.0|=2.9.1|=2.18.0|=2.17.1|=2.17.0|=2.16.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0|=2.8.0|=2.7.3|=2.7.2|=2.7.1|=2.7.0|=2.6.0|=2.5.1|=2.5.0|=2.4.0|=2.3.0|=2.2.1|=2.2.0|=2.1.0|=2.0.1|=2.0.0|=2.0.0-rc.1|=2.0.0-pre.1","fixed_version":"f582430498072a0c65ad338030321576dc13a343","source":"osv","published_at":"2026-07-28T09:54:19.579Z"},{"vuln_id":"CVE-2026-7790","severity":"high","summary":"Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS","affected_versions":">=0.6.0,<2.16.1|>=8c0e428b012c59f553a264f285ed89d36f791e3e,<a4b8039ce8c93ab00867ef6b7e888822c09f4369|=1.0.0|=1.0.1|=1.0.2|=1.1.0|=1.2.0|=1.3.0|=2.0.0|=2.0.1|=2.1.0|=2.10.0|=2.10.1|=2.11.0|=2.12.0|=2.12.1|=2.13.0|=2.14.0|=2.15.0|=2.16.0|=2.2.0|=2.2.1|=2.3.0|=2.4.0|=2.5.0|=2.5.1|=2.6.0|=2.7.0|=2.7.1|=2.7.2|=2.7.3|=2.8.0|=2.9.0|=2.9.1|=2.16.0|=2.15.0|=2.14.0|=2.13.0|=2.12.1|=2.12.0|=2.11.0|=2.10.1|=2.10.0|=2.9.1|=2.9.0|=2.8.0|=2.7.3|=2.7.2|=2.7.1|=2.7.0|=2.6.0|=2.5.1|=2.5.0|=2.4.0|=2.3.0|=2.2.1|=2.2.0|=2.1.0|=2.0.1|=2.0.0|=2.0.0-rc.1|=2.0.0-pre.1|=1.0.1|=1.3.0|=1.2.0|=1.1.0|=1.0.0|=0.6.2|=0.6.1|=0.6.0","fixed_version":"a4b8039ce8c93ab00867ef6b7e888822c09f4369","source":"osv","published_at":"2026-05-11T18:06:41.490Z"}]},"versions":{"latest":"2.20.0","total_count":38,"recent":["2.20.0","2.19.0","2.18.0","2.17.1","2.17.0","2.16.1","2.16.0","2.15.0","2.14.0","2.13.0","2.12.1","2.12.0","2.11.0","2.10.1","2.10.0","2.9.1","2.9.0","2.8.0","2.7.3","2.7.2"]},"metadata":{"deprecated":true,"deprecated_message":null,"maintainers_count":3,"first_published":"2014-08-01T16:06:22.000000Z","last_published":"2026-09-08T14:48:09.329731Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":296,"forks":191,"open_issues":15,"is_archived":false,"pushed_at":"2026-07-27T17:24:45+00:00"},"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"find_alternative","issues":["Moderate health score (35/100) — verify manually","3 high severity vulnerabilities","Package is deprecated"],"use_version":"2.20.0","version_hint":"Update to >= a4b8039ce8c93ab00867ef6b7e888822c09f4369 to fix known vulnerabilities","summary":"cowlib is deprecated — find an alternative"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/hex/cowlib","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/hex/cowlib","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/hex/cowlib","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}