CVE-2026-71380
Received Received - Intake

Denial of Service in Erlang/OTP inets httpd

Vulnerability report for CVE-2026-71380, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete. httpd_request_handler:handle_info/2 cancels the request timeout as soon as a parse step succeeds, which includes the headers, and the clause that handles a decoder asking for more data re-arms the socket with {active, once} without setting any further timer. httpd_request:whole_body/2 returns such a continuation whenever the bytes received are fewer than the announced Content-Length, so a well-formed request that stops mid-body leaves the worker waiting indefinitely. The periodic byte-rate check that would reclaim it is armed only when minimum_bytes_per_second is configured, which it is not by default. Repeating this across connections occupies every worker permitted by max_clients and denies service to legitimate clients at negligible bandwidth cost. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
erlang otp From 17.0 (inc) to 27.3.4.17 (exc)
erlang otp From 28.0 (inc) to 28.5.0.6 (exc)
erlang otp From 29.0 (inc) to 29.0.6 (exc)
erlang inets From 5.10 (inc) to 9.3.2.7 (exc)
erlang inets From 9.4 (inc) to 9.6.2.3 (exc)
erlang inets From 9.7 (inc) to 9.7.2 (exc)
erlang otp to 27.3.4.17 (exc)
erlang otp to 28.5.0.6 (exc)
erlang otp to 29.0.6 (exc)
erlang inets to 9.3.2.7 (exc)
erlang inets to 9.6.2.3 (exc)
erlang inets to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71380 is a Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP's inets httpd component. An unauthenticated remote attacker can cause a denial of service by sending a valid HTTP request with a large Content-Length header and then stalling before sending the complete request body. The httpd server cancels the request timeout after parsing headers but fails to re-arm it during body reception. This leaves worker processes parked indefinitely, consuming resources and eventually exhausting all available workers.

Detection Guidance

Monitor for sustained connections holding worker slots without completing requests. Check for unusually high numbers of active httpd workers or stalled connections in Erlang/OTP logs. Use network monitoring tools like netstat or ss to identify connections with large Content-Length headers that stall after partial body transmission.

Impact Analysis

This vulnerability allows attackers to deny service to legitimate users by occupying all worker slots with minimal bandwidth usage. A single attacker with 150 TCP connections can block all new connections in the default setup. The attack requires no authentication and works against default configurations. It can lead to complete service unavailability for users while consuming minimal server resources.

Mitigation Strategies

Upgrade Erlang/OTP to patched versions (27.3.4.17, 28.5.0.6, or 29.0.6). Set minimum_bytes_per_second in httpd configuration to enable periodic byte-rate checks. Deploy a reverse proxy with body-read timeouts in front of httpd. Reduce max_clients to limit worker exhaustion. Restrict server access to trusted clients only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71380. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart