Search CVE reports


Toggle filters

381 – 390 of 56887 results

Status is adjusted based on your filters.


CVE-2026-73812

Medium priority
Needs evaluation

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-73276

Medium priority
Needs evaluation

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-71380

Medium priority
Needs evaluation

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-70409

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-70405

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-70399

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-69664

Medium priority
Needs evaluation

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-59696

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits. uri_string:get_port/1...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-56855

Medium priority
Needs evaluation

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then,...

10 affected packages

golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...

Package 16.04 LTS
golang-1.17
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
golang-1.26
golang-1.27
golang-defaults Needs evaluation
Show all 10 packages Show less packages

CVE-2026-55951

Medium priority
Needs evaluation

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages