Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-71380

Erlang/OTP inets httpd workers wait forever on a request body that stops short of its Content-Length

Technology

Erlang/OTP

CVSS Score

8.7 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

inets httpd cancels the request timeout once the headers parse, and sets no new timer while it waits for more body data. A request with valid headers and a large Content-Length that then stalls keeps its worker waiting indefinitely, since the byte-rate check runs only when minimum_bytes_per_second is configured, which it is not by default. Repeating it denies service without authentication.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.