Erlang

Otp

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 01.09.2026 14:45:16
  • Zuletzt bearbeitet 08.09.2026 01:17:54

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, correspondin...

Medienbericht
  • EPSS 0.3%
  • Veröffentlicht 01.09.2026 14:42:42
  • Zuletzt bearbeitet 08.09.2026 01:17:54

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Conten...

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 01.09.2026 14:41:24
  • Zuletzt bearbeitet 08.09.2026 01:17:53

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, c...

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 01.09.2026 14:40:50
  • Zuletzt bearbeitet 08.09.2026 01:17:51

httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP...

Medienbericht
  • EPSS 0.42%
  • Veröffentlicht 01.09.2026 14:37:33
  • Zuletzt bearbeitet 08.09.2026 01:17:51

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits. uri_string:get_port/1 passes the port substr...

Medienbericht
  • EPSS 0.38%
  • Veröffentlicht 01.09.2026 14:37:02
  • Zuletzt bearbeitet 08.09.2026 01:17:50

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the...

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 01.09.2026 14:35:31
  • Zuletzt bearbeitet 08.09.2026 01:17:53

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before th...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 01.09.2026 14:33:41
  • Zuletzt bearbeitet 08.09.2026 01:17:53

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits. httpc_handler.er...

  • EPSS 0.53%
  • Veröffentlicht 01.09.2026 14:33:05
  • Zuletzt bearbeitet 08.09.2026 01:17:52

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is doc...

  • EPSS 0.29%
  • Veröffentlicht 27.07.2026 16:18:03
  • Zuletzt bearbeitet 10.08.2026 14:49:23

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 po...