HTTP Server Body Size Limit Bypass in Erlang OTP by Ericsson
CVE-2026-74835

8.7HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-74835?

The HTTP server component of Erlang's inets application fails to properly enforce a configured body-size limit for chunked requests, potentially allowing attackers to send maliciously crafted requests that may exceed the intended size restrictions. This vulnerability impacts various versions of Erlang OTP and its inets module, making it critical for users to ensure they are running patched versions to mitigate risks associated with this issue.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lukas Backström / Erlang Solutions
Konrad Pietrzak / Ericsson
.