Erlang/OTP 的 inets 模块中的 httpd 存在大小写处理不当漏洞。在文件系统为大小写不敏感的部署环境中,未经身份验证的远程攻击者可以通过使用不同的大小写形式请求文件,从而读取位于 受保护目录内的文件。 函数在判断解析后的文件系统路径是否位于受保护的目录块内部时,使用 对配置的目录路径进行正则匹配,但未启用“忽略大小写”选项。因此,当请求路径为 ,而配置的受保护目录为 时,两者因大小写不同而无法匹配,系统将该请求视为未受保护,不再发出身份验证挑战(authentication challenge)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-74835 | 8.7 HIGH | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
| CVE-2026-69664 | 8.7 HIGH | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-75538 | 8.2 HIGH | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into |
| CVE-2026-66835 | 8.2 HIGH | httpd mod_auth directory protection bypassed by a doubled slash in the request path |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
| CVE-2026-70405 | 6.3 MEDIUM | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-70409 | 6.3 MEDIUM | eldap does not bound the port component of a referral URL before integer conversion |
| CVE-2026-74994 | 6.0 MEDIUM | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
No comments yet