Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-66357

Erlang/OTP inets httpd request smuggling through obs-fold header continuation lines

Technology

Erlang/OTP

CVSS Score

8.3 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

inets httpd never implemented obs-fold header continuation lines and treats every line break followed by a non-blank line as a new header. A front-end proxy that folds those lines will see different headers from httpd, which allows HTTP request smuggling.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.