Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-79686 — Dell PowerStore Privilege Escalation Vulnerability

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gai…

Sep 01, 2026 Sep 02, 2026
Sep 01, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-79685 — Dell PowerStore Argument Injection Vulnerability

Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensi…

Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-78012 — Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. Th…

Remote | Memory Corruption
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.2 HIGH
CVE-2026-75538 — A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Int…

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer …

erlang\/otp otp | Remote | Memory Corruption
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-74994 — inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single …

erlang\/otp otp | Remote | Authentication
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-74835 — inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.3 HIGH
CVE-2026-73812 — inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_bo…

erlang\/otp otp | Remote | Injection
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.3 HIGH
CVE-2026-73276 — inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before O…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.2 HIGH
CVE-2026-73270 — httpd mod_auth directory protection bypassed by request path casing on case-insensitive f…

Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with diff…

erlang\/otp otp | Remote | Misconfiguration
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-71562 — httpc does not bound server-supplied numeric header values before integer conversion

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose va…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-71380 — httpd applies no timeout while receiving a request body, parking a worker on a stalled cl…

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-70409 — eldap does not bound the port component of a referral URL before integer conversion

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port compo…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-70405 — snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length f…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-70399 — httpd does not enforce the documented default max_clients connection limit

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large n…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-69664 — httpd parks a request worker indefinitely on a malformed chunk size sent after the headers

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked b…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 22, 2026
Sep 01, 2026
Sep 22, 2026
8.2 HIGH
CVE-2026-66835 — httpd mod_auth directory protection bypassed by a doubled slash in the request path

Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash…

erlang\/otp otp | Remote | Path Traversal
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.3 HIGH
CVE-2026-66357 — inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation

httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature bec…

erlang\/otp otp | Remote | Injection
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-59696 — uri_string does not bound the port component of a URI before integer conversion

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of di…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-58569 — Dell PowerStore Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execu…

Sep 01, 2026 Sep 04, 2026
Sep 01, 2026
Sep 04, 2026
8.2 HIGH
CVE-2026-55951 — httpc memory exhaustion via unbounded response header accumulation

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_header…

erlang\/otp otp | Remote | Denial of Service
Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
Showing 20 of 15023 Results