Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/inets

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-69664 is a high-severity vulnerability in Erlang/OTP's inets httpd component that allows unauthenticated remote attackers to cause a denial of service. The flaw arises when a request with a chunked body contains a chunk-size line that is not a hexadecimal number, causing the worker handling the connection to never be released. This leads to exhaustion of all available workers, denying service to legitimate clients. The vulnerability affects default configurations and multiple OTP and inets version ranges.

Join the discussion

CVE-2026-66835 is a Path Equivalence vulnerability in Erlang/OTP's inets httpd module that allows remote unauthenticated attackers to bypass authentication and read files inside mod_auth protected directories by using a request path with multiple leading slashes. The vulnerability arises because the URI normalization does not collapse empty path segments, allowing a doubled slash to survive and break the regex-based directory protection check. This affects multiple OTP and inets versions prior to specific fixed releases.

Join the discussion

CVE-2026-73270 is a high-severity vulnerability in Erlang/OTP's inets httpd module that improperly handles case sensitivity on case-insensitive filesystems. It allows remote unauthenticated attackers to bypass mod_auth directory protections by requesting files with different casing, leading to unauthorized file disclosure. This affects multiple OTP and inets versions prior to specific fixed releases. Case-sensitive filesystems are not affected.

Join the discussion

CVE-2026-74994 is an incorrect authorization vulnerability in the mod_auth module of the Erlang OTP inets httpd server. When configured with dets or mnesia authentication backends and multiple directory configuration blocks, all directory blocks share a single user/group namespace. This causes a user authorized for one protected directory to be accepted for all other protected directories on the same server instance. The issue affects multiple OTP and inets versions prior to specific fixed releases.

Join the discussion

CVE-2026-74835 is a high-severity vulnerability in the Erlang OTP inets HTTP server (httpd) where the configured body-size limit on chunked HTTP requests is not enforced. This flaw affects multiple OTP and inets versions, potentially allowing resource exhaustion due to allocation without limits or throttling. The vulnerability is identified as CWE-770. It has a CVSS 4.0 base score of 8.7, indicating a significant risk. The issue is fixed in OTP versions 27.3.4.17, 28.5.0.6, and 29.0.6 and corresponding inets versions 9.3.2.7, 9.6.2.3, and 9.7.2. No known exploits are reported in the wild. Patch status is not explicitly provided in the input, so users should consult the vendor advisory for remediation details.

Join the discussion

CVE-2026-73812 is a high-severity vulnerability in Erlang OTP's HTTP server (httpd) related to inconsistent interpretation of HTTP requests, specifically HTTP request/response smuggling. The issue arises because the httpd function check_header/3 rejects duplicate Content-Length headers but does not check for the simultaneous presence of Transfer-Encoding and Content-Length headers, which RFC 9112 §6.3 identifies as a probable smuggling attempt. This can cause desynchronization between front-end and back-end HTTP processing when a Content-Length-preferring front-end is paired with a chunked-preferring back-end. The vulnerability affects multiple OTP and inets versions as specified. No explicit patch links are provided in the data.

Join the discussion

CVE-2026-73276 is a high-severity vulnerability in Erlang OTP affecting multiple versions. It involves inconsistent interpretation of HTTP requests, specifically in the Gracefulness code, which ignored cases that should have been rejected. This flaw leads to HTTP Request Smuggling opportunities. The affected versions span OTP releases from 22.2 up to but not including 27.3.4.17, 28.0 up to but not including 28.5.0.6, and 29.0 up to but not including 29.0.6, as well as corresponding inets versions. The vulnerability has a CVSS 4.0 score of 8.3, indicating high severity. No information about available patches or vendor advisories is provided in the input.

Join the discussion

CVE-2026-66357 is a high-severity vulnerability in Erlang OTP's httpd component related to inconsistent interpretation of HTTP requests, specifically HTTP request/response smuggling. The issue arises because the httpd implementation never supported obs-fold (header continuation lines) as defined in RFC 2616 and RFC 7230, causing every CRLF followed by a non-CRLF octet to start a new header unconditionally. This behavior can lead to security concerns as HTTP request smuggling techniques evolve. The vulnerability affects multiple OTP and inets versions prior to specific fixed releases.

Join the discussion

CVE-2026-55951 is a vulnerability in the Erlang/OTP httpc HTTP client where there is no enforced limit on the total size of response headers received from a server. This allows a malicious or compromised HTTP server to send an arbitrarily large number or size of headers, causing unbounded memory allocation in the client process. This can lead to the BEAM VM crashing due to memory exhaustion. The issue affects multiple versions of OTP and the inets library before specific fixed versions.

Join the discussion

CVE-2026-71380 is a high-severity vulnerability in Erlang/OTP's inets httpd component that allows an unauthenticated remote attacker to cause a denial of service. The flaw arises from improper resource release after receiving partial HTTP request bodies with large Content-Length headers, leading to indefinite worker occupation. This affects multiple OTP and inets versions prior to specific fixed releases.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:github/inets
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses