CVE-2026-71380
Erlang/OTP inets httpd workers wait forever on a request body that stops short of its Content-Length
Technology
Erlang/OTP
CVSS Score
8.7 / 10.0
Affected Versions
OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)
Upstream Fix
OTP 27.3.4.17, 28.5.0.6, 29.0.6
Published
September 1, 2026
OSSeva Coverage
Fixed upstream
Description
inets httpd cancels the request timeout once the headers parse, and sets no new timer while it waits for more body data. A request with valid headers and a large Content-Length that then stalls keeps its worker waiting indefinitely, since the byte-rate check runs only when minimum_bytes_per_second is configured, which it is not by default. Repeating it denies service without authentication.
Is your Erlang/OTP deployment affected?
If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.