Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-66835— httpd mod_auth directory protection bypassed by a doubled slash in the request path

Quick assessment

Affected
Erlang OTP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Erlang/OTP 中的 inets httpd 存在路径等价性(Path Equivalence)漏洞,使得远程未认证的攻击者可以通过在请求路径前添加一个额外的斜杠,读取位于 保护目录内的文件。 具体机制如下: 使用 对请求 URI 进行规范化处理。该过程执行了 RFC 3986 中定义的“点段”(dot-segment)移除,但不会合并空路径段,因此连续的重复斜杠(如 )会被保留。 将文档根目录与规范化后的 URI 拼接成完整路径。 通过将被配置的保护目录路径作为未锚定的正则表达式在拼接后的路径上进行匹配,以

CVSS 8.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
httpd mod_auth directory protection bypassed by a doubled slash in the request path
Source: CVE Program / CVE List V5
Vulnerability Description
Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
路径等价:’//multiple/leading/slash’
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Erlang OTP 17.0 ~ 27.3.4.17 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 5.10 ~ 9.3.2.7 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 84adefa331c4159d432d22840663c38f155cd4c1 ~ * cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-66835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66835

登录查看更多情报信息。

Other References for CVE-2026-66835 (6)

Same Patch Batch · Erlang · 2026-09-01 · 16 CVEs total

CVE-2026-71380 8.7 HIGH httpd applies no timeout while receiving a request body, parking a worker on a stalled cli
CVE-2026-70399 8.7 HIGH httpd does not enforce the documented default max_clients connection limit
CVE-2026-74835 8.7 HIGH inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
CVE-2026-69664 8.7 HIGH httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
CVE-2026-66357 8.3 HIGH inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
CVE-2026-73812 8.3 HIGH inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
CVE-2026-73276 8.3 HIGH inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
CVE-2026-55951 8.2 HIGH httpc memory exhaustion via unbounded response header accumulation
CVE-2026-75538 8.2 HIGH A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into
CVE-2026-73270 8.2 HIGH httpd mod_auth directory protection bypassed by request path casing on case-insensitive fi
CVE-2026-59696 6.9 MEDIUM uri_string does not bound the port component of a URI before integer conversion
CVE-2026-71562 6.3 MEDIUM httpc does not bound server-supplied numeric header values before integer conversion
CVE-2026-70405 6.3 MEDIUM snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
CVE-2026-70409 6.3 MEDIUM eldap does not bound the port component of a referral URL before integer conversion
CVE-2026-74994 6.0 MEDIUM inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth

IV. Related Vulnerabilities

V. Comments for CVE-2026-66835

No comments yet


Leave a comment