PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66357 Erlang CVE debrief

CVE-2026-66357 is a high-severity vulnerability in the Erlang OTP inets component. The issue arises from the lack of support for HTTP header continuation lines, which can lead to HTTP request smuggling attacks. This vulnerability affects multiple OTP versions, including OTP 17.0 before OTP 27.3.4.17, OTP 28.0 before OTP 28.5.0.6, and OTP 29.0 before OTP 29.0.6. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. Defenders responsible for systems using Erlang OTP inets should assess exposure and apply patches or mitigations. This includes teams managing web servers, network infrastructure, and applications relying on Erlang OTP. The CVE record and NVD entry, 6

Vendor
Erlang
Product
OTP
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-01
Original CVE updated
2026-09-08
Advisory published
2026-09-01
Advisory updated
2026-09-08

Who should care

Defenders responsible for systems using Erlang OTP inets should assess exposure and apply patches or mitigations. This includes teams managing web servers, network infrastructure, and applications relying on Erlang OTP.

Why it matters

CVE-2026-66357 is a high-severity vulnerability in Erlang OTP inets, potentially allowing HTTP request smuggling attacks. Defenders should assess exposure, apply patches or mitigations, and monitor for potential attacks.

  • Potential for HTTP request smuggling attacks
  • Need to verify exposure and apply patches or mitigations
  • Possible impact on web server and network infrastructure security
  • Requirement to monitor for potential attacks

Technical summary

The Erlang OTP inets component does not support HTTP header continuation lines, which can lead to HTTP request smuggling attacks. This vulnerability affects multiple OTP versions, including OTP 17.0 before OTP 27.3.4.17, OTP 28.0 before OTP 28.5.0.6, and OTP 29.0 before OTP 29.0.6. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. The lack of support for HTTP header continuation lines can allow attackers to smuggle HTTP requests, potentially leading to security breaches. Defenders should prioritize assessing exposure and applying patches or mitigations, particularly for systems using affected OTP versions.

Defensive priority

Defenders should prioritize assessing exposure and applying patches or mitigations, particularly for systems using affected OTP versions.

Recommended defensive actions

  • Assess exposure by checking if your system uses an affected OTP version
  • Apply patches or mitigations for affected OTP versions
  • Verify the effectiveness of applied patches or mitigations
  • Monitor for potential HTTP request smuggling attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. However, the exact scope of affected systems and potential impact require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66357 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66357

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66357 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66357

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-66357.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/220d618d2479a7180b4a06d0c5aacfaa4af4a85b

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/273d8958de38ff2a7fe0c5dcc5b6bfe6f65717f3

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/e640d599287d2eba919e6f13b91f042d7dbe6ff4

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/security/advisories/GHSA-qh2f-33hj-37qf

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-66357

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.