Denial of Service Vulnerability in Erlang/OTP inets httpd
CVE-2026-69664

8.7HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-69664?

A missing resource release vulnerability in the Erlang/OTP inets httpd component can lead to a denial of service. An unauthenticated remote attacker can exploit this issue by sending incorrectly formatted requests, causing the server to retain connections indefinitely due to workers becoming occupied. The vulnerability arises when the server improperly handles the chunked transfer encoding, specifically when the chunk size is not in the expected hexadecimal format. This can lead to the exhaustion of available workers, thereby denying legitimate clients access. By default, this issue affects systems without additional configurations.

Affected Version(s)

OTP 18.1.4 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lukas Backström / Erlang Solutions
Konrad Pietrzak / Ericsson
Lukas Backström / Erlang Solutions
.