CVE-2026-73812
Received Received - Intake

HTTP Header Smuggling in Erlang OTP

Vulnerability report for CVE-2026-73812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 Β§6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
erlang otp From 17.0 (inc) to 27.3.4.17 (exc)
erlang otp From 28.0 (inc) to 28.5.0.6 (exc)
erlang otp From 29.0 (inc) to 29.0.6 (exc)
erlang inets From 5.10 (inc) to 9.3.2.7 (exc)
erlang inets From 9.4 (inc) to 9.6.2.3 (exc)
erlang inets From 9.7 (inc) to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an HTTP Request Smuggling issue in the Erlang/OTP inets and httpd applications. It occurs when HTTP requests contain both Transfer-Encoding and Content-Length headers, which RFC 9112 prohibits. The server fails to reject such requests, leading to a desynchronization between front-end and back-end systems (CL.TE desync). This allows attackers to smuggle additional requests within legitimate ones.

Detection Guidance

To detect this vulnerability, monitor HTTP traffic for requests containing both Transfer-Encoding and Content-Length headers. Use tools like tcpdump or Wireshark to capture and analyze packets for malformed requests. Check server logs for 400 Bad Request responses indicating rejected requests with dual headers.

Impact Analysis

An attacker could exploit this to bypass proxy access controls, poison responses for other users, or evade authentication enforced at the proxy layer. It may also enable session hijacking or data theft if deployed in a multi-user environment behind a reverse proxy.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using affected systems may face compliance failures and potential legal consequences.

Mitigation Strategies
  • Upgrade affected OTP versions to patched releases (27.3.4.17, 28.5.0.6, 29.0.6) or later.
  • Configure reverse proxies to reject requests with both Transfer-Encoding and Content-Length headers.
  • Use a proxy that normalizes requests by stripping Content-Length when Transfer-Encoding is present.
  • Disable httpd if not required or ensure it is not exposed behind a vulnerable proxy.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart