{"schema_version":1,"title":"Erlang Inets vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Erlang Inets: 0 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-74994, was published on 1 September 2026.","url":"https://junglewise.ai/threats/technologies/inets","json_url":"https://junglewise.ai/threats/technologies/inets.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/inets","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":15,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":11,"last_90_days":11,"last_365_days":15},"latest":[{"cve":"CVE-2026-74994","cvss":6,"epss":0.0063,"slug":"cve-2026-74994-otp-inets-httpd-mod-auth-directory-namespace-collapse","title":"OTP inets httpd mod_auth directory namespace collapse","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.927+00:00","url":"https://junglewise.ai/threats/cve-2026-74994-otp-inets-httpd-mod-auth-directory-namespace-collapse"},{"cve":"CVE-2026-74835","cvss":8.7,"epss":0.0058,"slug":"cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked","title":"Erlang OTP inets HTTP server body-size limit bypass in chunked requests","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.73+00:00","url":"https://junglewise.ai/threats/cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked"},{"cve":"CVE-2026-73812","cvss":8.3,"epss":0.0052,"slug":"cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and","title":"Erlang inets HTTP request smuggling via Transfer-Encoding and Content-Length","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.54+00:00","url":"https://junglewise.ai/threats/cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and"},{"cve":"CVE-2026-73276","cvss":8.3,"epss":0.0058,"slug":"cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace","title":"Erlang OTP inets HTTP request smuggling via header whitespace","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.367+00:00","url":"https://junglewise.ai/threats/cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace"},{"cve":"CVE-2026-73270","cvss":8.2,"epss":0.0093,"slug":"cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity","title":"Erlang/OTP inets httpd auth bypass via case sensitivity","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.103+00:00","url":"https://junglewise.ai/threats/cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity"},{"cve":"CVE-2026-71562","cvss":6.3,"epss":0.0058,"slug":"cve-2026-71562-erlang-otp-inets-httpc-unbounded-numeric-header-conversion-denial","title":"Erlang/OTP inets httpc unbounded numeric header conversion denial of service","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.883+00:00","url":"https://junglewise.ai/threats/cve-2026-71562-erlang-otp-inets-httpc-unbounded-numeric-header-conversion-denial"},{"cve":"CVE-2026-71380","cvss":8.7,"epss":0.0067,"slug":"cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body","title":"Erlang/OTP inets httpd denial of service via stalled request body","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.637+00:00","url":"https://junglewise.ai/threats/cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body"},{"cve":"CVE-2026-70399","cvss":8.7,"epss":0.0093,"slug":"cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited","title":"Erlang OTP inets httpd resource exhaustion via unlimited connections","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.947+00:00","url":"https://junglewise.ai/threats/cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited"},{"cve":"CVE-2026-66835","cvss":8.2,"epss":0.0097,"slug":"cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass","title":"Erlang/OTP inets httpd path equivalence authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.433+00:00","url":"https://junglewise.ai/threats/cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass"},{"cve":"CVE-2026-66357","cvss":8.3,"epss":0.0058,"slug":"cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header","title":"Erlang httpd HTTP request smuggling via obs-fold header continuation","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.047+00:00","url":"https://junglewise.ai/threats/cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header"},{"cve":"CVE-2026-55951","cvss":8.2,"epss":0.0069,"slug":"cve-2026-55951-erlang-otp-httpc-memory-exhaustion-via-unbounded-response-headers","title":"Erlang/OTP httpc memory exhaustion via unbounded response headers","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:20.78+00:00","url":"https://junglewise.ai/threats/cve-2026-55951-erlang-otp-httpc-memory-exhaustion-via-unbounded-response-headers"},{"cve":"CVE-2026-48858","cvss":6.3,"slug":"cve-2026-48858-erlang-otp-ssrf-in-ftp-internal-pasv-handler","title":"Erlang OTP SSRF in ftp_internal PASV handler","severity":"info","exploited":false,"published_at":"2026-06-10T16:17:11.077+00:00","url":"https://junglewise.ai/threats/cve-2026-48858-erlang-otp-ssrf-in-ftp-internal-pasv-handler"},{"cve":"CVE-2026-48856","cvss":7.1,"slug":"cve-2026-48856-erlang-otp-sensitive-header-leak-in-inets-httpc-redirect","title":"Erlang OTP sensitive header leak in inets httpc redirect","severity":"info","exploited":false,"published_at":"2026-06-10T16:17:10.053+00:00","url":"https://junglewise.ai/threats/cve-2026-48856-erlang-otp-sensitive-header-leak-in-inets-httpc-redirect"},{"cve":"CVE-2026-28808","cvss":9.8,"epss":0.005,"slug":"cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth","title":"Erlang OTP incorrect authorization in inets mod_auth","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:46.32+00:00","url":"https://junglewise.ai/threats/cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth"},{"cve":"CVE-2026-23941","cvss":9.4,"epss":0.0003,"slug":"cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd","title":"Erlang OTP HTTP Request Smuggling in inets httpd","severity":"critical","exploited":false,"published_at":"2026-03-13T19:54:15.237+00:00","url":"https://junglewise.ai/threats/cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Erlang OTP","slug":"otp","vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/otp"},{"name":"Erlang Ash","slug":"ash","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ash"},{"name":"Erlang Ssl","slug":"ssl","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ssl"},{"name":"Erlang public key","slug":"public-key","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/public-key"},{"name":"Erlang ERTS","slug":"erts","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/erts"}],"technology":{"hub":true,"name":"Erlang Inets","slug":"inets","vendor":{"name":"Erlang","slug":"erlang","url":"https://junglewise.ai/threats/vendors/erlang"},"aliases":[],"category":"library","homepage":"https://www.erlang.org/doc/apps/inets/index.html","repo_url":"https://github.com/erlang/otp","description":"A standard Erlang application providing a set of services including HTTP clients and servers, FTP, and TFTP.","url":"https://junglewise.ai/threats/technologies/inets"},"most_severe":[{"cve":"CVE-2026-28808","cvss":9.8,"epss":0.005,"slug":"cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth","title":"Erlang OTP incorrect authorization in inets mod_auth","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:46.32+00:00","url":"https://junglewise.ai/threats/cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth"},{"cve":"CVE-2026-23941","cvss":9.4,"epss":0.0003,"slug":"cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd","title":"Erlang OTP HTTP Request Smuggling in inets httpd","severity":"critical","exploited":false,"published_at":"2026-03-13T19:54:15.237+00:00","url":"https://junglewise.ai/threats/cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd"},{"cve":"CVE-2026-70399","cvss":8.7,"epss":0.0093,"slug":"cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited","title":"Erlang OTP inets httpd resource exhaustion via unlimited connections","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.947+00:00","url":"https://junglewise.ai/threats/cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited"},{"cve":"CVE-2026-71380","cvss":8.7,"epss":0.0067,"slug":"cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body","title":"Erlang/OTP inets httpd denial of service via stalled request body","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.637+00:00","url":"https://junglewise.ai/threats/cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body"},{"cve":"CVE-2026-74835","cvss":8.7,"epss":0.0058,"slug":"cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked","title":"Erlang OTP inets HTTP server body-size limit bypass in chunked requests","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.73+00:00","url":"https://junglewise.ai/threats/cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked"},{"cve":"CVE-2026-73276","cvss":8.3,"epss":0.0058,"slug":"cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace","title":"Erlang OTP inets HTTP request smuggling via header whitespace","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.367+00:00","url":"https://junglewise.ai/threats/cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace"},{"cve":"CVE-2026-66357","cvss":8.3,"epss":0.0058,"slug":"cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header","title":"Erlang httpd HTTP request smuggling via obs-fold header continuation","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.047+00:00","url":"https://junglewise.ai/threats/cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header"},{"cve":"CVE-2026-73812","cvss":8.3,"epss":0.0052,"slug":"cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and","title":"Erlang inets HTTP request smuggling via Transfer-Encoding and Content-Length","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.54+00:00","url":"https://junglewise.ai/threats/cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and"},{"cve":"CVE-2026-66835","cvss":8.2,"epss":0.0097,"slug":"cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass","title":"Erlang/OTP inets httpd path equivalence authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.433+00:00","url":"https://junglewise.ai/threats/cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass"},{"cve":"CVE-2026-73270","cvss":8.2,"epss":0.0093,"slug":"cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity","title":"Erlang/OTP inets httpd auth bypass via case sensitivity","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.103+00:00","url":"https://junglewise.ai/threats/cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}