HTTP Header Handling Vulnerability in Erlang OTP
CVE-2026-66357
8.3HIGH
What is CVE-2026-66357?
The Erlang OTP framework has a vulnerability related to HTTP header handling, specifically due to the non-implementation of obs-fold as per RFC 2616 and RFC 7230. This oversight results in improper processing of header continuation lines, allowing a CRLF followed by a non-CRLF octet to erroneously initiate new headers. As evolving threat models identify potential risks associated with HTTP request smuggling attacks, this vulnerability poses significant security concerns, particularly affecting various versions of OTP and inets components.
Affected Version(s)
OTP 17.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukas Backström / Erlang Solutions
Konrad Pietrzak / Ericsson
