Executive brief
The Erlang/OTP httpc HTTP client library does not limit the total size of response headers it accepts from servers. A malicious or compromised server can send an extremely large number of headers, forcing the client process to consume unbounded memory until the system runs out of RAM or the BEAM virtual machine crashes. This affects any application that uses httpc to fetch data from untrusted servers, including those accessed via redirects or man-in-the-middle scenarios.
Technical details
This is a resource exhaustion vulnerability (CWE-770) in the httpc HTTP client module of Erlang/OTP. The root cause is that httpc_response:parse_headers/6 accumulates all response headers into a list before performing length validation, which only triggers after receiving the final CRLF CRLF delimiter. The max_header_size option defaults to 'nolimit'. An attacker can exploit this by sending a large number of headers or headers with large values over the network without authentication. A proof-of-concept demonstration using 100,000 headers of ~4000 bytes each caused a client VM to allocate over 13 GB of memory in under 30 seconds. Patches have been released for OTP 27.3.4.17, 28.5.0.6, and 29.0.6.
Affected products
- Erlang OTP 17.0 through 27.3.4.16, 28.0 through 28.5.0.5, 29.0 through 29.0.5
- Erlang inets 5.10 through 9.3.2.6, 9.4 through 9.6.2.2, 9.7 through 9.7.1
Timeline
- 2026-09-01: disclosed: CVE-2026-55951 published
- 2026-09-01: patched: Patches released for OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6