CVE-2026-70399: httpd does not enforce the documented default max_clients connection limit
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The maxclients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/erlangto a version that resolves this vulnerability.Fixed in 1:29.0.6+dfsg-1Fixed in 1:29.1.1+dfsg-1 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in 27.3.4.17 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in 28.5.0.6 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in 29.0.6 - Upgrade
Upgrade
inetsto a version that resolves this vulnerability.Fixed in 9.3.2.7 - Upgrade
Upgrade
inetsto a version that resolves this vulnerability.Fixed in 9.6.2.3 - Upgrade
Upgrade
inetsto a version that resolves this vulnerability.Fixed in 9.7.2 - Configuration
Explicitly configure max_clients=150 to enforce the documented connection limit.
Erlang/OTP inets httpd max_clients = 150
Event History
Frequently Asked Questions
Which deployments are exposed?
Erlang/OTP inets httpd servers that do not explicitly set the max_clients option are exposed. Servers with max_clients explicitly configured are unaffected by this missing-default behavior.
What does an attacker need to do to trigger the denial of service?
An unauthenticated remote attacker only needs to establish and keep many connections open to the httpd service. No valid HTTP request or authentication is required.
What resources are consumed during an attack?
Each accepted held-open connection consumes a worker process and a socket. Sufficient connections can drive the node toward process, memory, and file descriptor exhaustion.
What can be done before a patch is available?
Explicitly configure max_clients to a numeric connection limit rather than relying on its documented default. Setting it explicitly restores enforcement of the configured limit; the documented default value is 150.