Summary
CVE-2026-69664 is a denial-of-service vulnerability in the httpd HTTP server component of Erlang/OTP’s inets package, caused by improper handling of malformed chunked transfer-encoding requests. An unauthenticated remote attacker can exhaust all available server workers, denying service to legitimate clients. The vulnerability has a CVSS score of 8.7 (High).
Technical details
- Root cause: when a chunked HTTP request’s chunk-size line arrives in a separate write from the headers, and that chunk-size line contains non-hexadecimal characters, the resulting error is converted into a return value instead of being handled properly, leaving the worker parked indefinitely.
- Trigger condition: the request timeout for the connection has already been cancelled by the time the malformed chunk-size line arrives, and no byte-rate check reclaims the worker by default.
- Attack vector: network, no authentication or user interaction required; the attacker sends a syntactically valid chunked request split across writes.
- Impact: repeating the attack across multiple connections exhausts all available httpd workers, resulting in denial of service to legitimate clients.
Affected software
- Erlang/OTP: 18.1.4 through 27.3.4.16
- Erlang/OTP: 28.0 through 28.5.0.5
- Erlang/OTP: 29.0 through 29.0.5
- inets package: 6.0.3 through 9.3.2.6
- inets package: 9.4 through 9.6.2.2
- inets package: 9.7 through 9.7.1
Severity
CVSS Score: 8.7 (High)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade to Erlang/OTP 27.3.4.17, 28.5.0.6, or 29.0.6 (inets 9.3.2.7, 9.6.2.3, or 9.7.2 respectively).
- If patching is not immediately possible:
- Configure the
minimum_bytes_per_secondhttpd setting to enforce byte-rate checks on incoming connections. - Deploy a reverse proxy in front of httpd that validates and rejects malformed chunked transfer-encoding requests.
- Restrict access to the httpd server to trusted clients where feasible.
- Configure the

