httpd 从未实现 obs-fold(RFC 2616 §2.2 / RFC 7230 §3.2.4 中的标题续行)。在 httpd 中,每一个由 CRLF 后紧跟非 CRLF 八位组的序列都会被无条件地视为一个新标题的开始。这一功能缺失在 HTTP 请求走私(request smuggling)攻击的理解不断深化的背景下,逐渐成为一个安全关注点。 该问题影响以下版本的 OTP: OTP 17.0 至 OTP 27.3.4.17 之前的版本; OTP 28.0 至 OTP 28.5.0.6 之前的版本; OTP
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
No comments yet