Allocation of Resources Without Limits or Throttling in Erlang OTP - CVE-2026-70399
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the inets httpd server when accepting simultaneous connections. A remote attacker can open a large number of connections and keep them open to cause a denial of service.
Only servers using the default configuration without an explicitly set max_clients value are vulnerable, and no valid request or user interaction is required.