Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause… (CVE-2026-71380)
A vulnerability in the Erlang/OTP inets httpd component allows unauthenticated remote attackers to cause a denial of service by sending valid HTTP headers with a large Content-Length and then stalling before the body is complete. This causes worker processes to wait indefinitely, exhausting available workers and denying service to legitimate clients. The issue affects multiple Erlang/OTP versions prior to fixed releases. Official patches are available from the vendor.
AI Analysis
Technical Summary
CVE-2026-71380 describes a missing release of resource vulnerability in Erlang/OTP's inets httpd server. The httpd_request_handler cancels request timeouts after headers are parsed but does not set further timers when waiting for the request body, allowing an attacker to stall connections by sending incomplete bodies with large Content-Length headers. Without the minimum_bytes_per_second configuration enabled (which is off by default), workers remain indefinitely occupied, leading to denial of service by exhausting max_clients workers. This affects OTP versions from 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, and 29.0 before 29.0.6, corresponding to inets versions from 5.10 before 9.3.2.7, 9.4 before 9.6.2.3, and 9.7 before 9.7.2. The vulnerability allows denial of service at negligible bandwidth cost.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by exhausting all available worker processes in the Erlang/OTP inets httpd server. This prevents legitimate clients from accessing the service. The attack requires minimal bandwidth and exploits the server's handling of incomplete HTTP request bodies. There is no indication of code execution or data compromise.
Mitigation Recommendations
A patch is available and should be applied to affected Erlang/OTP versions. The vendor advisory from Ubuntu (USN-8827-1) confirms fixes in updated package versions for multiple Ubuntu LTS releases. After applying updates, a system reboot is recommended to ensure all changes take effect. Configuring minimum_bytes_per_second may provide additional mitigation but is not enabled by default. Users should follow vendor instructions for updating Erlang packages to fixed versions.
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause… (CVE-2026-71380)
Description
A vulnerability in the Erlang/OTP inets httpd component allows unauthenticated remote attackers to cause a denial of service by sending valid HTTP headers with a large Content-Length and then stalling before the body is complete. This causes worker processes to wait indefinitely, exhausting available workers and denying service to legitimate clients. The issue affects multiple Erlang/OTP versions prior to fixed releases. Official patches are available from the vendor.
CVSS v4.0
Affected software
pkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/erlang?arch=source&distro=jammypkg:deb/ubuntu/erlang?arch=source&distro=noblepkg:deb/ubuntu/erlang?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71380 describes a missing release of resource vulnerability in Erlang/OTP's inets httpd server. The httpd_request_handler cancels request timeouts after headers are parsed but does not set further timers when waiting for the request body, allowing an attacker to stall connections by sending incomplete bodies with large Content-Length headers. Without the minimum_bytes_per_second configuration enabled (which is off by default), workers remain indefinitely occupied, leading to denial of service by exhausting max_clients workers. This affects OTP versions from 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, and 29.0 before 29.0.6, corresponding to inets versions from 5.10 before 9.3.2.7, 9.4 before 9.6.2.3, and 9.7 before 9.7.2. The vulnerability allows denial of service at negligible bandwidth cost.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by exhausting all available worker processes in the Erlang/OTP inets httpd server. This prevents legitimate clients from accessing the service. The attack requires minimal bandwidth and exploits the server's handling of incomplete HTTP request bodies. There is no indication of code execution or data compromise.
Mitigation Recommendations
A patch is available and should be applied to affected Erlang/OTP versions. The vendor advisory from Ubuntu (USN-8827-1) confirms fixes in updated package versions for multiple Ubuntu LTS releases. After applying updates, a system reboot is recommended to ensure all changes take effect. Configuring minimum_bytes_per_second may provide additional mitigation but is not enabled by default. Users should follow vendor instructions for updating Erlang packages to fixed versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-71380
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
- State
- PUBLISHED
Patch Information
Threat ID: 6abb4193f7a7c54106cc3803
Added to database: 09/29/2026, 04:41:55 UTC
Last enriched: 09/29/2026, 04:50:49 UTC
Last updated: 09/29/2026, 18:13:13 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.