Path Equivalence: \'//multiple/leading/slash\' in Erlang OTP - CVE-2026-66835
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose protected files.
The vulnerability exists due to path equivalence handling in inets httpd mod_auth directory protection when processing request paths with repeated leading slashes. A remote attacker can send a specially crafted request with an extra slash in the path to disclose protected files.
This requires an inets httpd deployment that enforces mod_auth on a directory block.