Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-73812

Erlang/OTP inets httpd accepts requests with both Transfer-Encoding and Content-Length

Technology

Erlang/OTP

CVSS Score

8.3 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

Since the fix for CVE-2026-23941, inets httpd rejects duplicate Content-Length headers, but it still accepts a request with both Transfer-Encoding and Content-Length, frames it as chunked and ignores Content-Length. Behind a front-end that prefers Content-Length this is a classic CL.TE request smuggling desync.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.