Am I affected?
type your erlang.org/otp version to check
Description
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request.
This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
Weaknesses & attack patterns
Weakness
CWE-770
·
Allocation of Resources Without Limits or Throttling
in catalog →
MITRE ↗
Affected — Erlang
<
17.0
status unknown
≥
17.0
<
27.3.4.17
affected
maint-28
≥
28.0
<
28.5.0.6
affected
maint-29
≥
29.0
<
29.0.6
affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
Affected — pkg:otp/inets Repository ↗
<
5.10
status unknown
≥
5.10
<
9.3.2.7
affected
≥
9.4
<
9.6.2.3
affected
≥
9.7
<
9.7.2
affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
Affected — GitHub / erlang/otp Repository ↗
≥
84adefa
and up
affected
→
0bceff0
not affected
→
8e1ca42
not affected
→
7f9c460
not affected
every other version:
unaffected
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
References
github.com/erlang/otp ·
GHSA-8qrh-x566-5xv5 ↗
vendor-advisory
osv.dev ·
EEF-CVE-2026-74835 ↗
related
Credits
Lukas Backström / Erlang Solutions
Finder
Konrad Pietrzak / Ericsson
Remediation developer
CVSS breakdown
HIGH 8.7
open in calculator →
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N