Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-55951

Erlang/OTP httpc client accepts unbounded response headers

Technology

Erlang/OTP

CVSS Score

8.2 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

The httpc HTTP client defaults max_header_size to nolimit and collects every header before checking length. A malicious or compromised HTTP server can send enough headers to exhaust client memory or crash the VM; the advisory's proof of concept made the client allocate over 13 GB.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.