Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-69664

Erlang/OTP inets httpd workers are never released after a malformed chunk-size line

Technology

Erlang/OTP

CVSS Score

8.7 / 10.0

Affected Versions

OTP 18.1.4 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

A chunked request whose chunk-size line is not hexadecimal leaves the inets httpd worker serving it occupied with no timeout. Repeating the request across connections ties up every worker and denies service. No authentication is needed and the default configuration is affected.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 18.1.4 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.