CVE-2026-69664
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no timeout reclaims it, so repeating the request across connections occupies every available worker and denies service to legitimate clients. No authentication is required and the default configuration is affected.
The chunk-size line must arrive in a write separate from the headers. When the body accompanies the headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 inside a try ... catch throw:Error, so the {error, {chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk size arrives later, the decoder is resumed through a bare catch in httpd_request_handler:handle_info/2, which converts the throw into a return value rather than raising it; the resulting error tuple is then treated as the next decoder continuation, the socket is re-armed, and the worker waits for data that never comes. The request timeout has already been cancelled at the point the headers were accepted, and the periodic byte-rate check is only armed when minimum_bytes_per_second is configured, which it is not by default.
Leer descripción completaMostrar menos
This issue affects OTP from OTP 18.1.4 before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6, corresponding to inets from 6.0.3 before 9.3.2.7, 9.6.2.3, and 9.7.2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.95%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 % - Impacto principal
T1499Endpoint Denial of Serviceimpact55 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-772
Referencias
- https://cna.erlef.org/cves/CVE-2026-69664.html
- https://github.com/erlang/otp/commit/77acb473d8f056f6f534395f131c6e45693797f0
- https://github.com/erlang/otp/commit/a3adf63078438c86527d704e23282b7721d8ca12
- https://github.com/erlang/otp/commit/bd4e74348c6be8a49f060da6fd48d43f3a960292
- https://github.com/erlang/otp/commit/df1a9ca4666e2fdfc44886bfaae76de086d803f6
- https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq
- https://osv.dev/vulnerability/EEF-CVE-2026-69664
- https://www.erlang.org/doc/system/versions.html#order-of-versions
- https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-69664",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-69664",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-01T17:44:51.976604Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
],
"vendor": "Erlang",
"modules": [
"http_chunk",
"httpd_request_handler"
],
"product": "OTP",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "27.3.4.17",
"status": "unaffected"
},
{
"at": "28.5.0.6",
"status": "unaffected"
},
{
"at": "29.0.6",
"status": "unaffected"
}
],
"version": "18.1.4",
"lessThan": "*",
"versionType": "otp"
}
],
"packageURL": "pkg:software-id/erlang.org/otp",
"packageName": "otp",
"programFiles": [
"lib/inets/src/http_lib/http_chunk.erl",
"lib/inets/src/http_server/httpd_request_handler.erl"
],
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "http_chunk:decode_size/4"
},
{
"name": "httpd_request_handler:handle_info/2"
},
{
"name": "httpd_request_handler:handle_body/3"
}
]
},
{
"cpes": [
"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/erlang/otp",
"vendor": "Erlang",
"modules": [
"http_chunk",
"httpd_request_handler"
],
"product": "OTP",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "9.3.2.7",
"status": "unaffected"
},
{
"at": "9.6.2.3",
"status": "unaffected"
},
{
"at": "9.7.2",
"status": "unaffected"
}
],
"version": "6.0.3",
"lessThan": "*",
"versionType": "otp"
}
],
"packageURL": "pkg:otp/inets",
"packageName": "inets",
"programFiles": [
"src/http_lib/http_chunk.erl",
"src/http_server/httpd_request_handler.erl"
],
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "http_chunk:decode_size/4"
},
{
"name": "httpd_request_handler:handle_info/2"
},
{
"name": "httpd_request_handler:handle_body/3"
}
]
},
{
"cpes": [
"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/erlang/otp",
"vendor": "Erlang",
"modules": [
"http_chunk",
"httpd_request_handler"
],
"product": "OTP",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "a3adf63078438c86527d704e23282b7721d8ca12",
"status": "unaffected"
},
{
"at": "df1a9ca4666e2fdfc44886bfaae76de086d803f6",
"status": "unaffected"
},
{
"at": "bd4e74348c6be8a49f060da6fd48d43f3a960292",
"status": "unaffected"
}
],
"version": "77acb473d8f056f6f534395f131c6e45693797f0",
"lessThan": "*",
"versionType": "git"
}
],
"packageURL": "pkg:github/erlang/otp",
"packageName": "erlang/otp",
"programFiles": [
"lib/inets/src/http_lib/http_chunk.erl",
"lib/inets/src/http_server/httpd_request_handler.erl"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "http_chunk:decode_size/4"
},
{
"name": "httpd_request_handler:handle_info/2"
},
{
"name": "httpd_request_handler:handle_body/3"
}
]
}
]
}
],
"published": "2026-09-01T15:17:23.677",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-69664.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/commit/77acb473d8f056f6f534395f131c6e45693797f0",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/commit/a3adf63078438c86527d704e23282b7721d8ca12",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/commit/bd4e74348c6be8a49f060da6fd48d43f3a960292",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/commit/df1a9ca4666e2fdfc44886bfaae76de086d803f6",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-69664",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-772"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no timeout reclaims it, so repeating the request across connections occupies every available worker and denies service to legitimate clients. No authentication is required and the default configuration is affected.\n\nThe chunk-size line must arrive in a write separate from the headers. When the body accompanies the headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 inside a try ... catch throw:Error, so the {error, {chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk size arrives later, the decoder is resumed through a bare catch in httpd_request_handler:handle_info/2, which converts the throw into a return value rather than raising it; the resulting error tuple is then treated as the next decoder continuation, the socket is re-armed, and the worker waits for data that never comes. The request timeout has already been cancelled at the point the headers were accepted, and the periodic byte-rate check is only armed when minimum_bytes_per_second is configured, which it is not by default.\n\nThis issue affects OTP from OTP 18.1.4 before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6, corresponding to inets from 6.0.3 before 9.3.2.7, 9.6.2.3, and 9.7.2."
}
],
"lastModified": "2026-09-22T10:17:09.610",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}