Erlang/OTP 中 eldap 组件存在输入指定数量校验不当的漏洞,使得恶意或已被攻陷的 LDAP 服务器可以通过返回一个端口部分为极长数字串的引用 URL 来降低系统可用性。 具体机制如下: 将端口子字符串直接传递给 ,且未对输入长度进行限制。 周围的 仅拒绝无法解析的值。因此,一个语法上有效、长度可达约 126 万位的端口数字串可以成功转换,但每次处理一个引用(referral)时,调用方需耗费数百毫秒执行任意精度算术运算。 由于该转换函数文档明确说明其可接受任意大小的整数,因此限制输入长度的责任在于调用
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-74835 | 8.7 HIGH | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
| CVE-2026-69664 | 8.7 HIGH | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-75538 | 8.2 HIGH | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into |
| CVE-2026-66835 | 8.2 HIGH | httpd mod_auth directory protection bypassed by a doubled slash in the request path |
| CVE-2026-73270 | 8.2 HIGH | httpd mod_auth directory protection bypassed by request path casing on case-insensitive fi |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
| CVE-2026-70405 | 6.3 MEDIUM | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-74994 | 6.0 MEDIUM | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
No comments yet