PatchSiren cyber security CVE debrief
CVE-2026-66357 Erlang CVE debrief
CVE-2026-66357 is a high-severity vulnerability in the Erlang OTP inets component. The issue arises from the lack of support for HTTP header continuation lines, which can lead to HTTP request smuggling attacks. This vulnerability affects multiple OTP versions, including OTP 17.0 before OTP 27.3.4.17, OTP 28.0 before OTP 28.5.0.6, and OTP 29.0 before OTP 29.0.6. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. Defenders responsible for systems using Erlang OTP inets should assess exposure and apply patches or mitigations. This includes teams managing web servers, network infrastructure, and applications relying on Erlang OTP. The CVE record and NVD entry, 6
- Vendor
- Erlang
- Product
- OTP
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for systems using Erlang OTP inets should assess exposure and apply patches or mitigations. This includes teams managing web servers, network infrastructure, and applications relying on Erlang OTP.
Why it matters
CVE-2026-66357 is a high-severity vulnerability in Erlang OTP inets, potentially allowing HTTP request smuggling attacks. Defenders should assess exposure, apply patches or mitigations, and monitor for potential attacks.
- Potential for HTTP request smuggling attacks
- Need to verify exposure and apply patches or mitigations
- Possible impact on web server and network infrastructure security
- Requirement to monitor for potential attacks
Technical summary
The Erlang OTP inets component does not support HTTP header continuation lines, which can lead to HTTP request smuggling attacks. This vulnerability affects multiple OTP versions, including OTP 17.0 before OTP 27.3.4.17, OTP 28.0 before OTP 28.5.0.6, and OTP 29.0 before OTP 29.0.6. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. The lack of support for HTTP header continuation lines can allow attackers to smuggle HTTP requests, potentially leading to security breaches. Defenders should prioritize assessing exposure and applying patches or mitigations, particularly for systems using affected OTP versions.
Defensive priority
Defenders should prioritize assessing exposure and applying patches or mitigations, particularly for systems using affected OTP versions.
Recommended defensive actions
- Assess exposure by checking if your system uses an affected OTP version
- Apply patches or mitigations for affected OTP versions
- Verify the effectiveness of applied patches or mitigations
- Monitor for potential HTTP request smuggling attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. However, the exact scope of affected systems and potential impact require further verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66357 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66357
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66357 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66357
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-66357.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/220d618d2479a7180b4a06d0c5aacfaa4af4a85b
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/273d8958de38ff2a7fe0c5dcc5b6bfe6f65717f3
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/e640d599287d2eba919e6f13b91f042d7dbe6ff4
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/security/advisories/GHSA-qh2f-33hj-37qf
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-66357
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.