攻击者若连接到一个开放且使用 驱动并启用 模式的 Erlang TCP 端口,可利用数据包长度计算中的符号溢出漏洞,导致接收缓冲区溢出,影响范围可延伸至 VM 分配器区域,最大可达约 2 GB。 该漏洞会轻易破坏已分配内存块的分配器元数据页脚(footer)以及下一个内存块(如果存在),并极有可能导致 BEAM 虚拟机崩溃。要利用此漏洞以足够精确的方式实现远程代码执行(RCE)极为困难,几乎不可行。 此问题影响以下版本: OTP 17.0 至 OTP 27.3.4.17 之前的版本 OTP 28.0 至 OTP 2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Erlang | OTP | 17.0 ~ 27.3.4.17 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 6.0 ~ 15.2.7.13 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 84adefa331c4159d432d22840663c38f155cd4c1 ~ 08e8efdba8500d2d6f54c6b1de1492b228017c9b |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71380 | 8.7 HIGH | httpd applies no timeout while receiving a request body, parking a worker on a stalled cli |
| CVE-2026-70399 | 8.7 HIGH | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-74835 | 8.7 HIGH | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
| CVE-2026-69664 | 8.7 HIGH | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
| CVE-2026-66357 | 8.3 HIGH | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73812 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-73276 | 8.3 HIGH | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
| CVE-2026-55951 | 8.2 HIGH | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-66835 | 8.2 HIGH | httpd mod_auth directory protection bypassed by a doubled slash in the request path |
| CVE-2026-73270 | 8.2 HIGH | httpd mod_auth directory protection bypassed by request path casing on case-insensitive fi |
| CVE-2026-59696 | 6.9 MEDIUM | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-71562 | 6.3 MEDIUM | httpc does not bound server-supplied numeric header values before integer conversion |
| CVE-2026-70405 | 6.3 MEDIUM | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
| CVE-2026-70409 | 6.3 MEDIUM | eldap does not bound the port component of a referral URL before integer conversion |
| CVE-2026-74994 | 6.0 MEDIUM | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
No comments yet