Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 27.1版本和6.1版本存在路径遍历漏洞,该漏洞源于stdlib zip模块中的相对路径遍历问题,允许通过特制zip归档文件将文件写入预期解压目录之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Erlang | OTP | 27.1 ~ * |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 6.1 ~ * |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 8d537f51a4262d24f3395c4148323eaca9facbbd ~ 8a933c9c7835b06776d31d17b79b7336627d887a |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55953 | 9.1 CRITICAL | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authent |
| CVE-2026-58227 | 8.7 HIGH | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain |
| CVE-2026-59251 | 8.7 HIGH | Denial of service via exponential certificate policy tree growth in path validation |
| CVE-2026-59250 | 8.3 HIGH | Megaco flex scanner buffer overflow via oversized property parm name |
| CVE-2026-54890 | 8.2 HIGH | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
| CVE-2026-42792 | 6.3 MEDIUM | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-55737 | 5.1 MEDIUM | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts e |
No comments yet