CVE-2026-28808: Erlang Inets Mod Alias Which Alias Missing Script Aliascve-2026-28808-erlang-inets-mod-alias-which-alias-missing-script-alias
Detected an inets `mod_alias`-style alias lookup that calls httpd_util:multi_lookup(ConfigDB, alias) without also concatenating httpd_util:multi_lookup(ConfigDB, script_alias). This is the vulnerable shape of `which_alias/1` from CVE-2026-28808: mod_auth derives the filesystem path used for `<Directory>` access-control matching from this list, so omitting `s