CVE-2026-70399
CVE-2026-70399: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-70399] Denial of Service via unenforced connection limit
CVE-2026-70399Source published Source updated
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required. The accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the…
- Affected products in this advisory
- Red Hat Hardened Images
- Source-reported affected versions
- < 17.0
- < 27.3.4.17
- < 28.0
- < 28.5.0.6
8 more entries in the full advisory.
- Source-reported fixed versions
- erlang27-main-27.3.4.17-0.1.hum1
- RHSA-2026:62531
- Mitigation guidance
- To mitigate this issue, explicitly configure the `max_clients` option in the Erlang/OTP inets httpd server configuration to a reasonable value. This will enforce a limit on simultaneous connections, preventing resource exhaustion. Consult the Erlang/OTP inets documentation for specific configuration instructions. A restart or reload of the affected service may be required for the changes to take effect, which could temporarily impact service availability.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.