CVE-2026-73276 PUBLISHED

inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i

Assigner: EEF
Reserved: 12.08.2026 Published: 01.09.2026 Updated: 01.09.2026

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.

This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 22.2 to 27.3.4.17 (excl.)
  • affected from 28.0 to 28.5.0.6 (excl.)
  • affected from 29.0 to 29.0.6 (excl.)
Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 7.1.2 to 9.3.2.7 (excl.)
  • affected from 9.4 to 9.6.2.3 (excl.)
  • affected from 9.7 to 9.7.2 (excl.)
Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from c06db0bedf49a9b40725745e73fa82e562612815 to * (excl.)

Credits

  • Konrad Pietrzak / Ericsson remediation developer
  • Lukas Backström / Erlang Solutions reporter

References

Problem Types

  • CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE

Impacts

  • CAPEC-33 HTTP Request Smuggling