CVE-2026-73812
httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.30%
- CWE
- CWE-444
- Published
- 2026-09-01
- Last modified
- 2026-09-08
Affected products
- Erlang OTP
- Erlang OTP
- Erlang OTP
- Erlang OTP
- Erlang OTP
- Erlang OTP
- Erlang OTP
- Erlang OTP
Weakness type
Related vulnerabilities
- CVE-2026-81356 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-19203 — A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty...
- CVE-2026-18540 — undici vulnerable to downstream response splitting via retry interceptor
- CVE-2026-84380 — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
- CVE-2026-84363 — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
- CVE-2026-78605 — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure
- CVE-2026-73276 — inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
- CVE-2026-66357 — inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation