Junglewise Threat Intelligence

CVE-2026-73270: Erlang/OTP inets httpd auth bypass via case sensitivity

CVE-2026-73270 · Severity: info · CVSS 8.2 · Published 2026-09-01

Technologies: Erlang Inets, Erlang OTP. Vendors: Erlang.

Executive brief

Erlang/OTP's inets httpd module protects sensitive directories using mod_auth authentication, but this protection can be bypassed on case-insensitive filesystems (Windows, macOS) by requesting files with different path casing. An attacker can read protected files without authentication by simply changing the case of directory names in the URL, allowing unauthorized access to sensitive data protected by authentication rules.

Technical details

This is an improper handling of case sensitivity vulnerability (CWE-178) in the mod_auth module of Erlang/OTP's inets httpd server. The vulnerability exists in mod_auth:secret_path/3, which uses re:run/3 to validate whether a request path falls within a protected directory block, but does not use the case-insensitive matching option. On case-insensitive filesystems, a request for /secret/file against a directory configured as /Secret will not match the regex pattern, bypassing authentication checks, while the filesystem itself resolves the mismatched casing to the same protected file and serves it. The attack requires network access to the httpd server and no authentication, but only succeeds on deployments using case-insensitive filesystems (default on Windows and macOS). Case-sensitive filesystems (Linux, Unix) are not affected because the filesystem itself rejects the mismatched path. Patches are available in OTP 27.3.4.17+, 28.5.0.6+, and 29.0.6+.

Affected products

  • Erlang OTP 17.0–27.3.4.16, 28.0–28.5.0.5, 29.0–29.0.5
  • Erlang inets 5.10–9.3.2.6, 9.4–9.6.2.2, 9.7–9.7.1

Timeline

  • 2026-09-01: disclosed
  • 2026-09-08: advisory: CNA advisory published

References

Related threats