Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-47078— Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass

Quick assessment

Affected
Erlang OTP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 27.1版本和6.1版本存在路径遍历漏洞,该漏洞源于stdlib zip模块中的相对路径遍历问题,允许通过特制zip归档文件将文件写入预期解压目录之外。

CVSS 4.8 · Medium EPSS 0.15% · P4

Affected Version Matrix 3

VendorProduct Version RangeStatus
Erlang OTP 27.1< * affected
6.1< * affected
8d537f51a4262d24f3395c4148323eaca9facbbd< 8a933c9c7835b06776d31d17b79b7336627d887a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-47078

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a running integer counter: .. decrements it, normal path components increment it. The caller rejects only paths where the final counter value is less than zero. A path such as ../x/y causes the counter to go negative mid-traversal then recover to zero, passing validation while resolving to a location outside the extraction directory when joined with the current working directory via add_cwd. This vulnerability is associated with program file lib/stdlib/src/zip.erl. This issue affects OTP from OTP 27.1 before OTP 27.3.4.15, OTP 28.5.0.4, and OTP 29.0.4, corresponding to stdlib from 6.1 before 6.2.2.4, 7.3.0.1, and 8.0.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5
Vulnerability Title
Erlang OTP 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 27.1版本和6.1版本存在路径遍历漏洞,该漏洞源于stdlib zip模块中的相对路径遍历问题,允许通过特制zip归档文件将文件写入预期解压目录之外。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Erlang OTP 27.1 ~ * cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 6.1 ~ * cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 8d537f51a4262d24f3395c4148323eaca9facbbd ~ 8a933c9c7835b06776d31d17b79b7336627d887a cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-47078

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-47078

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-47078 (2)

Vendor Advisories for CVE-2026-47078 (3)

Same Patch Batch · Erlang · 2026-07-27 · 8 CVEs total

CVE-2026-55953 9.1 CRITICAL TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authent
CVE-2026-58227 8.7 HIGH TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
CVE-2026-59251 8.7 HIGH Denial of service via exponential certificate policy tree growth in path validation
CVE-2026-59250 8.3 HIGH Megaco flex scanner buffer overflow via oversized property parm name
CVE-2026-54890 8.2 HIGH BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-42792 6.3 MEDIUM epmd permanent DoS via EMFILE on accept(2) in erts
CVE-2026-55737 5.1 MEDIUM Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts e

IV. Related Vulnerabilities

V. Comments for CVE-2026-47078

No comments yet


Leave a comment