erlang erlang/otp是erlang社区开源的一套并发编程语言及运行时系统。 Erlang/OTP存在加密问题漏洞,该漏洞源于通信信道中的消息完整性执行不当(tls_gen_connection模块问题),可能导致网络攻击者注入未经认证的明文数据并被视为已认证的服务器数据,攻击者在握手期间向客户端发送明文APPLICATION_DATA记录,在握手完成后传递给应用,影响仅限于盲注未经认证的字节。以下版本受到影响:17.0版本至29.0.3之前版本、28.5.0.3版本和27.3.4.14版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Erlang | OTP | 17.0 ~ 27.3.4.14 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 5.3.4 ~ 11.2.12.10 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 84adefa331c4159d432d22840663c38f155cd4c1 ~ 07d2d0e93f6aaf7652a81e8df075fc1728da5e96 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55950 | 8.7 HIGH | DTLS listener crash via race condition in dtls_packet_demux causes denial of service for a |
| CVE-2026-55952 | 8.2 HIGH | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension |
| CVE-2026-54887 | 6.3 MEDIUM | DTLS server cookie bypass during startup window due to empty initial cookie secret |
| CVE-2026-54886 | 5.3 MEDIUM | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-53422 | 2.3 LOW | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured roo |
No comments yet