erlang erlang/otp是erlang社区开源的一套并发编程语言及运行时系统。 Erlang/OTP存在输入验证错误漏洞,该漏洞源于ssl application未验证TLS 1.3 ClientHello预共享密钥扩展中PSK身份列表和绑定列表的长度是否相等,可能导致未经身份验证的远程攻击者发送特制ClientHello,造成会话票据处理进程崩溃,使TLS 1.3不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55950 | 8.7 HIGH | DTLS listener crash via race condition in dtls_packet_demux causes denial of service for a |
| CVE-2026-54887 | 6.3 MEDIUM | DTLS server cookie bypass during startup window due to empty initial cookie secret |
| CVE-2026-54891 | 6.3 MEDIUM | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application p |
| CVE-2026-54886 | 5.3 MEDIUM | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-53422 | 2.3 LOW | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured roo |
No comments yet