Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-55951
Erlang/OTP httpc client accepts unbounded response headers
Technology
Erlang/OTP
CVSS Score
8.2 / 10.0
Affected Versions
OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)
Upstream Fix
OTP 27.3.4.17, 28.5.0.6, 29.0.6
Published
September 1, 2026
OSSeva Coverage
Fixed upstream
Description
The httpc HTTP client defaults max_header_size to nolimit and collects every header before checking length. A malicious or compromised HTTP server can send enough headers to exhaust client memory or crash the VM; the advisory's proof of concept made the client allocate over 13 GB.
Is your Erlang/OTP deployment affected?
If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.