#VU125768 Open redirect in otp - CVE-2016-1000107
Published: April 10, 2026
otp
erlang
Description
The vulnerability allows a remote attacker to redirect an application's outbound HTTP traffic to an arbitrary proxy server.
The vulnerability exists due to environment variable pollution in mod_cgi when processing a crafted Proxy header in an HTTP request. A remote attacker can send a specially crafted request to redirect an application's outbound HTTP traffic to an arbitrary proxy server.
User interaction is required.