cbcvebase.
CVE-2026-74835
published 2026-09-01

CVE-2026-74835: The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP…

PriorityP352high8.7CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.33%
25.6th percentile
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

Affected

10 ranges
VendorProductVersion rangeFixed in
cryostatcryostat-storage-rhel9
devspacestraefik-rhel9
erlangotp>= 17.0 < 27.3.4.1727.3.4.17
erlangotp>= 28.0 < 28.5.0.628.5.0.6
erlangotp>= 29.0 < 29.0.629.0.6
erlangotp>= 5.10 < 9.3.2.79.3.2.7
erlangotp>= 84adefa331c4159d432d22840663c38f155cd4c1 < **
erlangotp>= 9.4 < 9.6.2.39.6.2.3
erlangotp>= 9.7 < 9.7.29.7.2
rhacm2volsync-rhel9

CVSS provenance

nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.