Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-74835

Erlang/OTP inets httpd ignores the body size limit for chunked requests

Technology

Erlang/OTP

CVSS Score

8.7 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

inets httpd does not enforce a configured body size limit when the request body is chunked, so a client can send an unbounded body and exhaust the server's memory.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.