这段漏洞描述涉及 Erlang/OTP 中 inets 库的一个具体问题。以下是准确、专业的中文翻译,保留了技术术语和版本号: 翻译: 优雅模式(Gracefulness)代码忽略了本应被拒绝的情况,从而可能引发 HTTP 请求走私(HTTP Request Smuggling)漏洞。 该问题影响以下版本的 OTP: OTP 22.2 至 OTP 27.3.4.17 之前的版本 OTP 28.0 至 OTP 28.5.0.6 之前的版本 OTP 29.0 至 OTP 29.0.6 之前的版本 对应 inets 库的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
No comments yet