CVE-2026-66835
Received Received - Intake

Path Equivalence Flaw in Erlang/OTP inets httpd

Vulnerability report for CVE-2026-66835, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
erlang otp to 27.3.4.17 (exc)
erlang otp to 28.5.0.6 (exc)
erlang otp to 29.0.6 (exc)
erlang inets to 9.3.2.7 (exc)
erlang inets to 9.6.2.3 (exc)
erlang inets to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-50 The product accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Erlang/OTP's inets httpd allows a remote attacker to bypass authentication and read protected files by adding an extra slash to the request path. The system fails to properly normalize paths, letting the attacker access files meant to be restricted by mod_auth.

Detection Guidance

Check Erlang/OTP and inets versions. Affected versions are OTP 17.0 to 27.3.4.16, 28.0 to 28.5.0.5, and 29.0 to 29.0.5. Use commands like 'erl -version' or 'erl -eval 'io:format("~s~n", [erlang:system_info(otp_release)]), halt().' to verify.

Impact Analysis

An attacker could exploit this to access sensitive files without authentication, potentially stealing data or bypassing security controls. Systems using affected OTP versions (17.0 to 29.0.5) or inets versions (5.10 to 9.7.1) are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive files protected by mod_auth, potentially violating data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., unauthorized access to protected health information).

Mitigation Strategies

Upgrade Erlang/OTP to OTP 27.3.4.17 or later, OTP 28.5.0.6 or later, or OTP 29.0.6 or later. Also update inets to 9.3.2.7, 9.6.2.3, or 9.7.2 or newer depending on your OTP version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart