PatchSiren cyber security CVE debrief
CVE-2026-74835 Erlang CVE debrief
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests, affecting OTP versions before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6. This issue, tracked as CVE-2026-74835, has a CVSS score of 8.7 and is considered HIGH severity. The vulnerability impacts OTP and inets deployments, particularly those using versions before OTP 17.0. Defenders should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions.
- Vendor
- Erlang
- Product
- OTP
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for OTP and inets deployments, especially those using versions before OTP 17.0, should assess exposure and prioritize verification and potential remediation. They should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions. This includes reviewing and applying patches or updates from the vendor once available and considering inventory checks for systems using affected OTP
Why it matters
CVE-2026-74835 is a HIGH-severity vulnerability in the inets application HTTP server httpd, affecting OTP and inets deployments. Defenders should verify exposure, assess the need for compensating controls, and prioritize patching or updating affected versions.
- Verify exposure in OTP and inets deployments, especially for versions before OTP 17.0.
- Assess the need for compensating controls, such as limiting request sizes or monitoring for suspicious activity.
- Prioritize patching or updating affected OTP and inets versions.
Technical summary
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. The vulnerability has a CVSS score of 8.7 and is considered HIGH severity. Defenders should prioritize verifying exposure in their OTP and inets deployments, especially for versions before OTP 17.0, and assess the need for compensating controls.
Defensive priority
Defenders should prioritize verifying exposure in their OTP and inets deployments, especially for versions before OTP 17.0, and assess the need for compensating controls.
Recommended defensive actions
- Verify OTP and inets versions in your environment against the affected versions.
- Assess the need for compensating controls, such as limiting request sizes or monitoring for suspicious activity.
- Review and apply patches or updates from the vendor once available.
- Consider inventory checks for systems using affected OTP and inets versions.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the affected scope for OTP versions before 17.0 is unknown and requires further verification. The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0,
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-74835.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/0bceff0c2987cae83d9d4a77c5ecacd6d01b8b86
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/7f9c460d1818c2afb78fbd01f8d8b81343bbb011
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/8e1ca42b64df6c41306affbe8dc129bdbd4042c7
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/security/advisories/GHSA-8qrh-x566-5xv5
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-74835
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.