Description
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.

The accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses. Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion. Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended.

This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.
Published: 2026-09-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unlimited concurrent connections
Action: Patch immediately
AI Analysis

Impact

The vulnerability arises from Erlang/OTP’s inets httpd component failing to enforce its documented default maximum client limit of 150. When this option is not explicitly set, the accept gate interprets the missing value as undefined rather than the default, allowing an attacker to open an unrestricted number of simultaneous connections without authentication or a valid request. Each connection consumes a worker process and a socket, rapidly exhausting system resources such as memory, file descriptors, and process slots, which can bring the node or entire host down.

Affected Systems

The issue affects Erlang/OTP deployments that use the inets httpd module. Specifically, any OTP release prior to OTP 27.3.4.17, OTP 28.5.0.6, or OTP 29.0.6 is vulnerable. This includes inets releases 5.10 before 9.3.2.7, 9.4 before 9.6.2.3, and 9.7 before 9.7.2. Systems running these versions without an explicitly configured max_clients value are impacted.

Risk and Exploitability

The CVSS score of 8.7 signals a high severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the exploitation probability cannot be quantified but the lack of authentication and the ability to saturate resources makes successful attacks likely in a practical setting. The attack vector is inferred to be remote, via any network interface that can connect to the httpd service, as no credentials are required and the attacker only needs the ability to open TCP connections.

Generated by OpenCVE AI on September 1, 2026 at 15:53 UTC.

Remediation

Vendor Workaround

* Set max_clients explicitly in the httpd configuration, for example {max_clients, 150}. An explicitly configured value is read by the same accept gate and applied as intended, so this restores the documented limit without upgrading. * Limit concurrent connections in front of httpd, for example with reverse proxy or firewall connection-count and connection-rate rules. * Restrict access to the server to trusted clients where the deployment allows it.


OpenCVE Recommended Actions

  • Upgrade Erlang/OTP to a version that includes the fix (OTP 27.3.4.17 or newer, OTP 28.5.0.6 or newer, or OTP 29.0.6 or newer).
  • As an interim measure, explicitly configure max_clients in the httpd configuration, for example {max_clients, 150}.
  • Use an external reverse proxy or firewall to limit concurrent connections and/or apply connection‑rate rules.

Generated by OpenCVE AI on September 1, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Erlang erlang/otp
Erlang otp
Vendors & Products Erlang erlang/otp
Erlang otp
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required. The accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses. Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion. Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.
Title httpd does not enforce the documented default max_clients connection limit
First Time appeared Erlang
Erlang erlang\/otp
Weaknesses CWE-770
CPEs cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Vendors & Products Erlang
Erlang erlang\/otp
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Erlang Erlang/otp Erlang\/otp Otp
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T01:08:41.997Z

Reserved: 2026-08-06T13:00:02.045Z

Link: CVE-2026-70399

cve-icon Vulnrichment

Updated: 2026-09-01T15:52:49.600Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T15:17:23.947

Modified: 2026-09-08T01:17:52.707

Link: CVE-2026-70399

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-01T14:33:05Z

Links: CVE-2026-70399 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling