CVE-2026-23941Disclosure(erlang / erlang\/inets)

LOWCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for erlang erlang\/inets systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. The server does not reject or normalize duplicate Content-Length headers. The earliest Content-Length in the request is used for body parsing while common reverse proxies (nginx, Apache httpd, Envoy) honor the last Content-Length value. This violates RFC 9112 Section 6.3 and allows front-end/back-end desynchronization, leaving attacker-controlled bytes queued as the start of the next request. This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to inets from 5.10 before 9.6.1, 9.3.2.3 and 9.1.0.5.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erlang\/inets
  • erlang\/otp

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
erlang\/inetserlang\/otp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-13: 1Mentions · 2026-03-19: 1Active Exploitation · 2026-03-19: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-19: 103-1303-19
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-191
Active Exploitation1
Full discourse2 posts
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.602 – Jeudi 19 mars 2026 Neuf sujets. Veille cyber quotidienne. 🔴 KEV / CISA – Ajout de CVE-2026-20131 affectant Cisco Secure Firewall et CVE-2026-20963 impactant Microsoft SharePoint. Deux vulnérabilités de type Deserialization of Untrusted Data activement exploitées. 🔴 Endpoint Management – La CISA alerte sur une attaque visant Stryker avec abus de Microsoft Intune. Exploitation de privilèges et détournement de capacités d’administration centralisée. 🔴 Ubiquiti – Vulnérabilité critique dans UniFi Network affectant plusieurs versions. Impact non documenté mais exposition directe des consoles de gestion réseau. 🔴 CERT-FR / Microsoft – Multiples vulnérabilités référencées CVE-2026-23941 à CVE-2026-4111. Impact non spécifié, dépendances Erlang, libexif et libarchive concernées. 🔴 Roundcube – Vulnérabilités multiples incluant SSRF, XSS et CSRF sur Webmail. Atteinte à la confidentialité et exécution de requêtes côté serveur possibles. 🔴 Mitel – Vulnérabilité XSS affectant MiContact Center et MCX. Injection de code côté client permettant manipulation de session et contenu. 🔴 Splunk – Vulnérabilités multiples dans Universal Forwarder. Références CVE-2025-15467, CVE-2026-22795 et CVE-2026-22796. Impact non précisé. 🔴 Python – CVE-2026-3479. Contournement de politique de sécurité dans CPython. Mécanisme d’exploitation non détaillé publiquement. 🔴 VMware Tanzu – Plus de 100 CVE dans les Buildpacks et composants plateforme. Risque Supply Chain étendu sur dépendances logicielles. 🔴 DPRK – IBM X-Force et Flare identifient une opération impliquant 100 000 faux IT workers infiltrant des entreprises occidentales. Usage de VPN, identités frauduleuses et plateformes freelance. 🔴 NCSC – Publication de recommandations sur la sécurisation des visioconférences. Risques liés aux accès, à la gestion des données et aux fonctionnalités IA. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-602-radiocsirt-edition-francaise-veille-cyber-du-jeudi-19-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Cisco #SharePoint #Deserialization #Endpoint #Intune #Ubiquiti #UniFi #CERTFR #Roundcube #SSRF #XSS #CSRF #Mitel #Splunk #Python #VMware #Tanzu #SupplyChain #NorthKorea #DPRK #IBM #Flare #NCSC #ZeroTrust #CVE #CERT #SOC #CISO #CyberDefense #BlueTeam #InfoSec

    Post summary

    The episode highlights that CVE‑2026‑20131 (Cisco Secure Firewall) and CVE‑2026‑20963 (Microsoft SharePoint) are actively exploited via deserialization vulnerabilities, among other CVEs discussed across multiple vendors.

    00000101
    413 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23941 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-23941

    Post summary

    The entry identifies CVE‑2026‑23941 as an HTTP Request Smuggling vulnerability in Erlang OTP’s inets httpd module, without mentioning active exploitation, PoC, or patches.

    00000105
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apperlangerlang\/inets---
Apperlangerlang\/otp---

Explore more