CVE-2026-73812
Last modified
CVE-2026-73812 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Erlang | OTP | < 17.0; >= 17.0, < 27.3.4.17; >= 28.0, < 28.5.0.6; >= 29.0, < 29.0.6 |
| Erlang | OTP | < 5.10; >= 5.10, < 9.3.2.7; >= 9.4, < 9.6.2.3; >= 9.7, < 9.7.2 |
| Erlang | OTP | >= 84adefa331c4159d432d22840663c38f155cd4c1, < 591dc00dc99dc2a426167a3b5257c0c94bd45e91 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-73812?
How severe is CVE-2026-73812?
How do I fix CVE-2026-73812?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73789A vulnerability in the web-based management interface of CPP…5.3
- CVE-2026-7379Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 all…7.5
- CVE-2026-7380Improper neutralization of Script-Related HTML tags in a web…6.1
- CVE-2026-73807The mySCADA myPRO Manager command API does not properly enfo…9.8
- CVE-2026-73809A cleartext transmission of sensitive information vulnerabil…7.5
- CVE-2026-7381Plack::Middleware::XSendfile versions through 1.0053 for Per…9.1
- CVE-2026-73819The affected Ebyte product's vendor configuration utility …9.8
- CVE-2026-7382Exposure of Sensitive Information to an Unauthorized Actor, …6.5
- CVE-2026-73827SOY Calendar contains a cross-site scripting vulnerability. …4.8
- CVE-2026-73829Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive…3.7
- CVE-2026-7383Issue summary: A signed integer overflow when sizing the des…8.1
- CVE-2026-73834A flaw was found in the must-gather component of Red Hat Adv…5.5
Are you affected by CVE-2026-73812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
