Erlang
Erlang Inets: vulnerabilidades y CVE
Erlang Inets tiene 13 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-74994 | Media (6) | 0.63% | — | 1 sept 2026 | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group… |
| CVE-2026-74835 | Alta (8.7) | 0.58% | — | 1 sept 2026 | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0… |
| CVE-2026-73812 | Alta (8.3) | 0.52% | — | 1 sept 2026 | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by… |
| CVE-2026-73276 | Alta (8.3) | 0.58% | — | 1 sept 2026 | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from… |
| CVE-2026-73270 | Alta (8.2) | 0.93% | — | 1 sept 2026 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on… |
| CVE-2026-71562 | Media (6.3) | 0.58% | — | 1 sept 2026 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long… |
| CVE-2026-71380 | Alta (8.7) | 0.67% | — | 1 sept 2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large… |
| CVE-2026-70399 | Alta (8.7) | 0.93% | — | 1 sept 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of… |
| CVE-2026-66835 | Alta (8.2) | 0.97% | — | 1 sept 2026 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash.… |
| CVE-2026-66357 | Alta (8.3) | 0.58% | — | 1 sept 2026 | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security… |
| CVE-2026-55951 | Alta (8.2) | 0.69% | — | 1 sept 2026 | The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates… |
| CVE-2026-69664 | Alta (8.7) | 0.95% | — | 1 sept 2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size… |
| CVE-2026-21620 | Baja (2.3) | 0.48% | — | 20 feb 2026 | Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.