CVE-2026-23941 | Erlang OTP RFC 9112 httpd_request.erl Content-Length request smuggling (Nessus ID 302363 / WID-SEC-2026-0721)
A vulnerability described as problematic has been identified in Erlang OTP. Affected by this issue is some unknown functionality in the library lib/inets/src/http_server/httpd_request.erl of the component RFC 9112. Executing a manipulation of the argument Content-Length can lead to http request smuggling.
The identification of this vulnerability is CVE-2026-23941. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.