Improper Handling of Case Sensitivity Vulnerability in Erlang/OTP inets httpd
CVE-2026-73270
8.2HIGH
What is CVE-2026-73270?
An improper handling of case sensitivity in the Erlang/OTP inets httpd module allows remote unauthenticated attackers to access files located in a mod_auth protected directory by manipulating the casing of the requested URLs. This flaw arises when the configured directory path is processed without a caseless mode, permitting potential circumvention of authentication checks in environments utilizing case-insensitive filesystems. Conversely, systems operating on case-sensitive filesystems are not subject to this vulnerability due to their inherent capacity to reject incorrectly cased requests.
Affected Version(s)
OTP 17.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Konrad Pietrzak / Ericsson
Lukas Backström / Erlang Solutions
