以下是该漏洞描述的中文翻译: 资源生命周期结束后未释放(Missing Release of Resource after Effective Lifetime)漏洞 Erlang/OTP 的 模块存在一个“资源生命周期结束后未释放”的漏洞。一个未经身份验证的远程攻击者可以通过发送一个块体(chunked body)请求来触发拒绝服务(DoS),其中块大小行(chunk-size line)不是十六进制数字。处理该连接的 worker 进程永远不会被释放,且没有超时机制将其回收,因此,如果在多个连接上重复发送此请求
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-74835 | 8.7 HIGH | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-75538 | 8.2 HIGH | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into |
| CVE-2026-66835 | 8.2 HIGH | httpd mod_auth directory protection bypassed by a doubled slash in the request path |
| CVE-2026-73270 | 8.2 HIGH | httpd mod_auth directory protection bypassed by request path casing on case-insensitive fi |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
| CVE-2026-70405 | 6.3 MEDIUM | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-70409 | 6.3 MEDIUM | eldap does not bound the port component of a referral URL before integer conversion |
| CVE-2026-74994 | 6.0 MEDIUM | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
No comments yet