CVE-2026-71562
Received Received - Intake

Denial of Service in Erlang OTP httpc

Vulnerability report for CVE-2026-71562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits. httpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1 before comparing it against max_body_size, so the size check cannot protect the conversion, and the option defaults to nolimit in any case. The same unbounded conversion appears in httpc_response:format_response/1 for Content-Length and in httpc_response:get_ms_from_retry_after/1 for Retry-After, which is guarded only by a check that the first character is a digit. A value of up to roughly 1.26 million digits converts successfully and costs the requesting process hundreds of milliseconds of arbitrary-precision arithmetic per response. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
erlang otp to 27.3.4.17 (exc)
erlang otp to 28.5.0.6 (exc)
erlang otp to 29.0.6 (exc)
erlang inets to 9.3.2.7 (exc)
erlang inets to 9.6.2.3 (exc)
erlang inets to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Denial-of-Service vulnerability in Erlang/OTP's inets httpc component where a malicious HTTP server can send extremely long numeric headers like Content-Length. The httpc module fails to properly validate these values before converting them to integers, causing the system to perform slow arbitrary-precision arithmetic. This consumes excessive CPU resources and degrades system availability.

Detection Guidance

Monitor for unusually high CPU usage on Erlang/OTP systems running affected versions. Check HTTP responses for extremely long numeric headers like Content-Length or Retry-After. Use network traffic analysis tools to detect malformed headers.

Impact Analysis

An attacker could exploit this to slow down or crash your Erlang/OTP applications by sending specially crafted HTTP responses with very long numeric headers. This could lead to degraded performance, unresponsive services, or even system outages if the affected application handles many such requests.

Mitigation Strategies

Upgrade Erlang/OTP to patched versions 27.3.4.17, 28.5.0.6, or 29.0.6. If upgrading is not possible, restrict network access to trusted HTTP servers or implement header size validation at the network perimeter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71562. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart