PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74835 Erlang CVE debrief

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests, affecting OTP versions before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6. This issue, tracked as CVE-2026-74835, has a CVSS score of 8.7 and is considered HIGH severity. The vulnerability impacts OTP and inets deployments, particularly those using versions before OTP 17.0. Defenders should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions.

Vendor
Erlang
Product
OTP
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-01
Original CVE updated
2026-09-08
Advisory published
2026-09-01
Advisory updated
2026-09-08

Who should care

Defenders responsible for OTP and inets deployments, especially those using versions before OTP 17.0, should assess exposure and prioritize verification and potential remediation. They should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions. This includes reviewing and applying patches or updates from the vendor once available and considering inventory checks for systems using affected OTP

Why it matters

CVE-2026-74835 is a HIGH-severity vulnerability in the inets application HTTP server httpd, affecting OTP and inets deployments. Defenders should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions.

  • Verify exposure in OTP and inets deployments, especially for versions before OTP 17.0.
  • Assess the need for compensating controls, such as limiting request sizes or monitoring for suspicious activity.
  • Prioritize patching or updating affected OTP and inets versions.

Technical summary

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. The vulnerability has a CVSS score of 8.7 and is considered HIGH severity. Defenders should prioritize verifying exposure in their OTP and inets deployments, especially for versions before OTP 17.0, and assess the need for compensating controls.

Defensive priority

Defenders should prioritize verifying exposure in their OTP and inets deployments, especially for versions before OTP 17.0, and assess the need for compensating controls.

Recommended defensive actions

  • Verify OTP and inets versions in your environment against the affected versions.
  • Assess the need for compensating controls, such as limiting request sizes or monitoring for suspicious activity.
  • Review and apply patches or updates from the vendor once available.
  • Consider inventory checks for systems using affected OTP and inets versions.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the affected scope for OTP versions before 17.0 is unknown and requires further verification. The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74835 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74835

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74835 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74835

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-74835.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/0bceff0c2987cae83d9d4a77c5ecacd6d01b8b86

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/7f9c460d1818c2afb78fbd01f8d8b81343bbb011

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/8e1ca42b64df6c41306affbe8dc129bdbd4042c7

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/security/advisories/GHSA-8qrh-x566-5xv5

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-74835

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.