Junglewise Threat Intelligence

CVE-2026-23941: Erlang OTP HTTP Request Smuggling in inets httpd

CVE-2026-23941 · Severity: critical · CVSS 9.4 · Published 2026-03-13

Technologies: Erlang OTP, Erlang Inets. Vendors: Erlang.

Executive brief

A vulnerability in the Erlang OTP web server module (inets httpd) could allow attackers to bypass security controls or hijack user sessions. By sending specially crafted web requests with conflicting information, an attacker can 'smuggle' hidden commands past a security proxy directly to the backend server. This can lead to unauthorized access to sensitive data, cache poisoning, or the disruption of legitimate user requests.

Technical details

The Erlang OTP 'inets' httpd module fails to properly validate or reject requests containing multiple Content-Length headers, violating RFC 9112 Section 6.3. The server follows a 'first-wins' strategy, parsing the body based on the earliest Content-Length header, while many common reverse proxies (like Nginx or Apache) follow a 'last-wins' strategy. An attacker can exploit this discrepancy to desynchronize the connection, leaving malicious bytes in the server's buffer that are interpreted as the start of a subsequent request. This can result in authentication bypass, request hijacking, or web cache poisoning. The issue is fixed in OTP versions 28.4.1, 27.3.4.9, and 26.2.5.18.

Affected products

  • Erlang OTP 17.0 to 26.2.5.17, 27.0 to 27.3.4.8, 28.0 to 28.4.0
  • Erlang inets 5.10 to 9.1.0.4, 9.3 to 9.3.2.2, 9.6 to 9.6.0

Timeline

  • 2026-03-13: disclosed
  • 2026-03-13: advisory
  • 2026-03-13: patched

References