Technology · Erlang
Erlang Inets vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in Erlang Inets: 0 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-74994, was published on 1 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 2
- Exploited in the wild
- 0
About Erlang Inets
A standard Erlang application providing a set of services including HTTP clients and servers, FTP, and TFTP.
Latest Erlang Inets vulnerabilities
- CVE-2026-74994: OTP inets httpd mod_auth directory namespace collapseinfoCVSS 6EPSS 0.6%
- CVE-2026-74835: Erlang OTP inets HTTP server body-size limit bypass in chunked requestsinfoCVSS 8.7EPSS 0.6%
- CVE-2026-73812: Erlang inets HTTP request smuggling via Transfer-Encoding and Content-LengthinfoCVSS 8.3EPSS 0.5%
- CVE-2026-73276: Erlang OTP inets HTTP request smuggling via header whitespaceinfoCVSS 8.3EPSS 0.6%
- CVE-2026-73270: Erlang/OTP inets httpd auth bypass via case sensitivityinfoCVSS 8.2EPSS 0.9%
- CVE-2026-71562: Erlang/OTP inets httpc unbounded numeric header conversion denial of serviceinfoCVSS 6.3EPSS 0.6%
- CVE-2026-71380: Erlang/OTP inets httpd denial of service via stalled request bodyinfoCVSS 8.7EPSS 0.7%
- CVE-2026-70399: Erlang OTP inets httpd resource exhaustion via unlimited connectionsinfoCVSS 8.7EPSS 0.9%
- CVE-2026-66835: Erlang/OTP inets httpd path equivalence authentication bypassinfoCVSS 8.2EPSS 1.0%
- CVE-2026-66357: Erlang httpd HTTP request smuggling via obs-fold header continuationinfoCVSS 8.3EPSS 0.6%
- CVE-2026-55951: Erlang/OTP httpc memory exhaustion via unbounded response headersinfoCVSS 8.2EPSS 0.7%
- CVE-2026-48858: Erlang OTP SSRF in ftp_internal PASV handlerinfoCVSS 6.3
- CVE-2026-48856: Erlang OTP sensitive header leak in inets httpc redirectinfoCVSS 7.1
- CVE-2026-28808: Erlang OTP incorrect authorization in inets mod_authcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23941: Erlang OTP HTTP Request Smuggling in inets httpdcriticalCVSS 9.4EPSS 0.0%
Most severe Erlang Inets vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-28808: Erlang OTP incorrect authorization in inets mod_authcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23941: Erlang OTP HTTP Request Smuggling in inets httpdcriticalCVSS 9.4EPSS 0.0%
- CVE-2026-70399: Erlang OTP inets httpd resource exhaustion via unlimited connectionsinfoCVSS 8.7EPSS 0.9%
- CVE-2026-71380: Erlang/OTP inets httpd denial of service via stalled request bodyinfoCVSS 8.7EPSS 0.7%
- CVE-2026-74835: Erlang OTP inets HTTP server body-size limit bypass in chunked requestsinfoCVSS 8.7EPSS 0.6%
- CVE-2026-73276: Erlang OTP inets HTTP request smuggling via header whitespaceinfoCVSS 8.3EPSS 0.6%
- CVE-2026-66357: Erlang httpd HTTP request smuggling via obs-fold header continuationinfoCVSS 8.3EPSS 0.6%
- CVE-2026-73812: Erlang inets HTTP request smuggling via Transfer-Encoding and Content-LengthinfoCVSS 8.3EPSS 0.5%
- CVE-2026-66835: Erlang/OTP inets httpd path equivalence authentication bypassinfoCVSS 8.2EPSS 1.0%
- CVE-2026-73270: Erlang/OTP inets httpd auth bypass via case sensitivityinfoCVSS 8.2EPSS 0.9%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 11 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/inets.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Erlang Inets vulnerabilities", https://junglewise.ai/threats/technologies/inets, 26 September 2026.