Erlang/OTP 中的 inets httpd 存在路径等价性(Path Equivalence)漏洞,使得远程未认证的攻击者可以通过在请求路径前添加一个额外的斜杠,读取位于 保护目录内的文件。 具体机制如下: 使用 对请求 URI 进行规范化处理。该过程执行了 RFC 3986 中定义的“点段”(dot-segment)移除,但不会合并空路径段,因此连续的重复斜杠(如 )会被保留。 将文档根目录与规范化后的 URI 拼接成完整路径。 通过将被配置的保护目录路径作为未锚定的正则表达式在拼接后的路径上进行匹配,以
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-74835 | 8.7 HIGH | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
| CVE-2026-69664 | 8.7 HIGH | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-75538 | 8.2 HIGH | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into |
| CVE-2026-73270 | 8.2 HIGH | httpd mod_auth directory protection bypassed by request path casing on case-insensitive fi |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
| CVE-2026-70405 | 6.3 MEDIUM | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-70409 | 6.3 MEDIUM | eldap does not bound the port component of a referral URL before integer conversion |
| CVE-2026-74994 | 6.0 MEDIUM | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
No comments yet