Denial of Service Exposure in Erlang/OTP inets httpd
CVE-2026-71380

8.7HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-71380?

A vulnerability exists in the Erlang/OTP inets httpd component, where an unauthenticated remote attacker can exploit missing resource release after the effective lifetime, leading to potential denial of service. By sending valid request headers with a large Content-Length and then stalling the request body, attackers can cause the affected httpd server to wait indefinitely. This behavior can exhaust server resources, preventing legitimate users from accessing services. This issue specifically affects multiple versions of OTP and inets, complicating the landscape for developers and system administrators who must ensure their environments are secure.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Konrad Pietrzak / Ericsson
Lukas Backström / Erlang Solutions
.