See how open telecom platform compares to other vendors in security performance
httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved.
Heap pointer corruption via signed/unsigned mismatch in LARGETUPLEEXT decoding in erts external term format decoder