Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-73276

Erlang/OTP inets httpd request smuggling through whitespace before the header colon

Technology

Erlang/OTP

CVSS Score

8.3 / 10.0

Affected Versions

OTP 22.2 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

Lenient header parsing in inets httpd accepted malformed headers, such as whitespace between a header name and its colon, that should be rejected, which opens HTTP request smuggling when httpd sits behind a proxy that reads them differently.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 22.2 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.