以下是对该漏洞描述信息的中文翻译: Erlang/OTP inets 模块中的 httpd 存在“资源在有效生命周期结束后未释放”的漏洞。未认证的远程攻击者可以通过发送带有大 字段的合法请求头,随后在请求体传输完成前停滞(stalling),从而造成服务拒绝(DoS)。 技术细节: 在解析步骤(包括请求头)成功时立即取消了请求超时定时器;而处理“解码器请求更多数据”的子句会将 socket 重新设置为 ,但未设置任何后续定时器。当接收到的字节数少于声明的 时, 会返回一个等待更多数据的 continuation。因
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Erlang | OTP | 17.0 ~ 27.3.4.17 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 5.10 ~ 9.3.2.7 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 84adefa331c4159d432d22840663c38f155cd4c1 ~ 81b453aac5a006bb8d26405f2bc3cf24e9d7733c |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
No comments yet