PT-2026-84257 · Otp+1 · Otp+1
CVE-2026-66357
·
Published
2026-09-01
·
Updated
2026-09-01
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
OTP versions 17.0 through 27.3.4.16
OTP versions 28.0 through 28.5.0.5
OTP versions 29.0 through 29.0.5
inets versions 5.10 through 9.3.2.6
inets versions 9.4 through 9.6.2.2
inets versions 9.7 through 9.7.1
Description
httpd does not implement obs-fold, a feature regarding header continuation lines. Consequently, every Carriage Return Line Feed (CRLF) followed by a non-CRLF octet is unconditionally treated as the start of a new header. This lack of implementation creates a risk for HTTP request smuggling attacks, where an attacker can interfere with the way a website processes sequences of HTTP requests.
Recommendations
Update OTP to version 27.3.4.17 or later.
Update OTP to version 28.5.0.6 or later.
Update OTP to version 29.0.6 or later.
Update inets to version 9.3.2.7 or later.
Update inets to version 9.6.2.3 or later.
Update inets to version 9.7.2 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otp
Inets