CVE-2026-55951
Received Received - Intake

Memory Exhaustion in Erlang OTP httpc Client

Vulnerability report for CVE-2026-55951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF is received). A malicious or compromised HTTP server can send an arbitrarily large number of headers, or headers with very large values, causing the client process to allocate unbounded memory until the system runs out of memory or the BEAM VM crashes. A proof-of-concept server sending 100,000 headers of roughly 4000 bytes each caused the client VM to allocate over 13 GB of memory in under 30 seconds. Any application using httpc:request/4,5 to connect to untrusted servers is affected. No authentication is required: any server the client connects to (including via a redirect or man-in-the-middle) can trigger the exhaustion. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
erlang otp From 17.0 (exc) to 27.3.4.17 (exc)
erlang otp From 28.0 (exc) to 28.5.0.6 (exc)
erlang otp From 29.0 (exc) to 29.0.6 (exc)
erlang inets From 5.10 (exc) to 9.3.2.7 (exc)
erlang inets From 9.4 (exc) to 9.6.2.3 (exc)
erlang inets From 9.7 (exc) to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Erlang/OTP HTTP client library (httpc) due to a lack of limits on response header size. The default max_header_size setting is nolimit, and the parsing function accumulates all headers before performing a length check. A malicious server can send an excessive number of headers or very large header values, causing unbounded memory allocation in the client process.

Detection Guidance

Monitor BEAM VM memory usage and process crashes when connecting to HTTP servers. Check for excessive header sizes in HTTP responses using tools like tcpdump or Wireshark to inspect traffic. Look for processes using httpc:request/4 or /5 with untrusted servers.

Impact Analysis

The vulnerability can cause system-wide resource exhaustion, leading to the BEAM VM crashing or the system running out of memory. It impacts any application using httpc:request/4 or httpc:request/5 to connect to untrusted servers, including those accessed via redirects or man-in-the-middle attacks.

Compliance Impact

This vulnerability could lead to denial-of-service (DoS) conditions by exhausting system resources, which may violate availability requirements in GDPR (Article 32) and HIPAA (Security Rule Β§164.308(a)(7)). Uncontrolled memory allocation could also impact integrity and confidentiality if services fail or logs are disrupted.

Mitigation Strategies

Upgrade to patched OTP versions (27.3.4.17, 28.5.0.6, 29.0.6) or newer. Restrict httpc to trusted servers only. Apply OS-level memory limits (e.g., cgroups, ulimit). Use alternative HTTP clients with header size enforcement if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart