PT-2026-84267 · Inets · Inets

CVE-2026-74835

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions inets versions 5.10 through 9.3.2.6 inets versions 9.4 through 9.6.2.2 inets versions 9.7 through 9.7.1
Description The inets application HTTP server httpd fails to enforce a configured body-size limit when processing chunked requests. Chunked requests are a mechanism in HTTP that allows a server to send data to a client in a series of chunks, which is useful when the total content length is unknown at the start of the transmission.
Recommendations Update inets versions 5.10 through 9.3.2.6 to version 9.3.2.7. Update inets versions 9.4 through 9.6.2.2 to version 9.6.2.3. Update inets versions 9.7 through 9.7.1 to version 9.7.2.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98493
CVE-2026-74835
GHSA-8QRH-X566-5XV5

Affected Products

Inets