CVE-2026-73812 is an HTTP request-smuggling vulnerability in the Erlang/OTP inets httpd component. The check_header/3 function rejects duplicate Content-Length headers but does not reject requests containing both Transfer-Encoding and Content-Length. The handle_body/3 function processes such requests as chunked transfer encoding and silently discards Content-Length. When httpd is deployed behind a Content-Length-preferring front end, the differing framing interpretations can cause CL.TE front-end/back-end request desynchronization. The issue affects OTP 17.0 through versions before 27.3.4.17, OTP 28.0 through versions before 28.5.0.6, and OTP 29.0 through versions before 29.0.6. The impact on OTP releases before 17.0 is unknown.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by Ubuntu USN-8827-1 for Erlang packages.
A critical, network-accessible Erlang vulnerability affecting specified Ubuntu LTS and Debian releases, with no privileges or user interaction required. The stated impact is high integrity and availability impact; confidentiality impact is none in CVSS v3 and low in CVSS v4.
A referenced Erlang/OTP vulnerability affecting vulnerable FreeBSD Erlang runtime packages.
High-severity HTTP request-smuggling vulnerability (CWE-444) in Erlang/OTP's inets httpd. Improper handling of simultaneous Transfer-Encoding and Content-Length headers can cause a CL.TE request desynchronization between a Content-Length-preferring front end and chunked-transfer-preferring inets back end.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.