Denial of Service Exposure in Erlang/OTP inets httpd
CVE-2026-71380
What is CVE-2026-71380?
A vulnerability exists in the Erlang/OTP inets httpd component, where an unauthenticated remote attacker can exploit missing resource release after the effective lifetime, leading to potential denial of service. By sending valid request headers with a large Content-Length and then stalling the request body, attackers can cause the affected httpd server to wait indefinitely. This behavior can exhaust server resources, preventing legitimate users from accessing services. This issue specifically affects multiple versions of OTP and inets, complicating the landscape for developers and system administrators who must ensure their environments are secure.
Affected Version(s)
OTP 17.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
