CyberRota Analysis
AI-GeneratedThe inets application HTTP server (httpd) is vulnerable due to its failure to enforce a configured body-size limit on chunked requests, potentially allowing attackers to exploit this weakness for denial-of-service or resource exhaustion attacks. This issue impacts various versions of the Erlang/OTP framework, specifically those prior to specified patch levels, and should be prioritized by organizations using affected versions to mitigate potential security risks. System administrators and developers relying on these versions should urgently apply the necessary updates to safeguard their applications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.