Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.63% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected… | |
| Aplazada | Alta (8.7) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from… | |
| Aplazada | Alta (8.3) | 0.52% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring… | |
| Aplazada | Alta (8.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before… | |
| Aplazada | Alta (8.2) | 0.93% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive. mod_auth:secret_path/3 decides whether a resolved… | |
| Aplazada | Media (6.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits. httpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1… | |
| Aplazada | Alta (8.7) | 0.67% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete. httpd_request_handler:handle_info/2 cancels the… | |
| Aplazada | Alta (8.7) | 0.93% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents… | |
| Aplazada | Alta (8.2) | 0.97% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986… | |
| Aplazada | Alta (8.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved. This issue affects OTP from OTP… | |
| Aplazada | Alta (8.2) | 0.69% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF… | |
| Aplazada | Alta (8.7) | 0.95% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 22/9/2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no… | |
| Modificada | Media (6.3) | 0.23% | — | Erlang/inetsErlang/otpErlang FTP | 10/6/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server's 227… | |
| Modificada | Alta (7.1) | 0.34% | — | Erlang/inetsErlang/otp | 10/6/2026 | 24/9/2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2… | |
| Modificada | Alta (8.3) | 0.77% | — | Erlang/inetsErlang/otp | 7/4/2026 | 8/9/2026 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the… | |
| Modificada | Alta (7) | 0.45% | — | Erlang/inetsErlang/otp | 13/3/2026 | 24/7/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. The server does not… | |
| Aplazada | Baja (2.3) | 0.48% | — | Erlang OTPAIErlang InetsAIErlang TftpAI | 20/2/2026 | 24/7/2026 | Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl,… | |
| Modificada | Media (6.1) | 0.91% | — | Inetsoftware I-net Clear Reports | 9/3/2021 | 17/6/2026 | I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect. | |
| Modificada | Crítica (9.8) | 1.1% | — | Inetsoftware I-net Clear Reports | 15/7/2020 | 17/6/2026 | XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser. | |
| Modificada | Crítica (9.1) | 2.1% | — | Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc | 7/5/2020 | 17/6/2026 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal. | |
| Modificada | Media (5) | 1.6% | — | Inetstore Online | 9/1/2006 | 16/6/2026 | Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Infinetsoftware Mytemplatesite | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 2.6% | — | Avtronics Inetserv | 22/8/2001 | 16/6/2026 | Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password. | |
| Modificada | Alta (10) | 13% | — | Avtronics Inetserv | 17/1/2000 | 16/6/2026 | Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. |