Am I affected?
type your erlang.org/otp version to check
Description
Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.
This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.
Weaknesses & attack patterns
Weakness
CWE-444
·
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
in catalog →
MITRE ↗
Attack patterns
CAPEC-33
·
HTTP Request Smuggling
MITRE ↗
Affected — Erlang
≥
22.2
<
27.3.4.17
affected
maint-28
≥
28.0
<
28.5.0.6
affected
maint-29
≥
29.0
<
29.0.6
affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
Affected — pkg:otp/inets Repository ↗
≥
7.1.2
<
9.3.2.7
affected
≥
9.4
<
9.6.2.3
affected
≥
9.7
<
9.7.2
affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
Affected — GitHub / erlang/otp Repository ↗
≥
c06db0b
and up
affected
→
60add5a
not affected
→
6cd995e
not affected
→
c285240
not affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
References
github.com/erlang/otp ·
GHSA-6v7q-jwgh-cx8p ↗
vendor-advisory
osv.dev ·
EEF-CVE-2026-73276 ↗
related
Credits
Konrad Pietrzak / Ericsson
Remediation developer
Lukas Backström / Erlang Solutions
Reporter
CVSS breakdown
HIGH 8.3
open in calculator →
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N