EEF-CVE-2026-73276

Source
https://cna.erlef.org/osv/EEF-CVE-2026-73276.html
Import Source
https://cna.erlef.org/osv/EEF-CVE-2026-73276.json
JSON Data
https://api.osv.dev/v1/vulns/EEF-CVE-2026-73276
Aliases
Published
2026-09-01T14:41:24.565Z
Modified
2026-09-01T14:55:41.869444048Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Details

Summary

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.

This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.

Database specific
{
    "cwe_ids": [
        "CWE-444"
    ],
    "capec_ids": [
        "CAPEC-33"
    ],
    "cpe_ids": [
        "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
    ]
}
References
Credits
    • Konrad Pietrzak / Ericsson - REMEDIATION_DEVELOPER
    • Lukas Backström / Erlang Solutions - REPORTER

Affected packages

Git / github.com/erlang/otp

Database specific

source
"https://cna.erlef.org/osv/EEF-CVE-2026-73276.json"