HTTP Request Smuggling Vulnerability in Erlang OTP's inets Module
CVE-2026-23941

7HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-23941?

An inconsistency in how the Erlang OTP inets httpd module processes HTTP requests can lead to HTTP Request Smuggling. Specifically, the module fails to properly handle duplicate Content-Length headers, utilizing the earliest value for body parsing while common reverse proxies, such as nginx and Apache, adhere to the last Content-Length header. This misalignment can create a desynchronization between front-end and back-end components, allowing attackers to craft requests that may exploit this desynchronization and queue malicious bytes for subsequent requests. The vulnerability affects multiple versions of Erlang OTP and its inets module, emphasizing the need for organizations to assess their implementations and apply relevant patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

OTP 5.10

OTP pkg:otp/inets@5.10

OTP 17.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luigino Camastra / Aisle Research
Konrad Pietrzak
.