Improper Handling of Case Sensitivity Vulnerability in Erlang/OTP inets httpd
CVE-2026-73270

8.2HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-73270?

An improper handling of case sensitivity in the Erlang/OTP inets httpd module allows remote unauthenticated attackers to access files located in a mod_auth protected directory by manipulating the casing of the requested URLs. This flaw arises when the configured directory path is processed without a caseless mode, permitting potential circumvention of authentication checks in environments utilizing case-insensitive filesystems. Conversely, systems operating on case-sensitive filesystems are not subject to this vulnerability due to their inherent capacity to reject incorrectly cased requests.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Konrad Pietrzak / Ericsson
Lukas Backström / Erlang Solutions
.