PT-2026-84267 · Inets · Inets
CVE-2026-74835
·
Published
2026-09-01
·
Updated
2026-09-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
inets versions 5.10 through 9.3.2.6
inets versions 9.4 through 9.6.2.2
inets versions 9.7 through 9.7.1
Description
The inets application HTTP server httpd fails to enforce a configured body-size limit when processing chunked requests. Chunked requests are a mechanism in HTTP that allows a server to send data to a client in a series of chunks, which is useful when the total content length is unknown at the start of the transmission.
Recommendations
Update inets versions 5.10 through 9.3.2.6 to version 9.3.2.7.
Update inets versions 9.4 through 9.6.2.2 to version 9.6.2.3.
Update inets versions 9.7 through 9.7.1 to version 9.7.2.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inets