Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 23.2版本至29.0.4之前版本、28.5.0.4版本和27.3.4.15版本存在资源管理错误漏洞,该漏洞源于在TLS或DTLS握手重建不完整的对等证书链时未检测循环,导致未经身份验证的远程攻击者可通过发送特制证书链,耗尽内存并导致BEAM节点崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55953 | 9.1 CRITICAL | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authent |
| CVE-2026-59251 | 8.7 HIGH | Denial of service via exponential certificate policy tree growth in path validation |
| CVE-2026-59250 | 8.3 HIGH | Megaco flex scanner buffer overflow via oversized property parm name |
| CVE-2026-54890 | 8.2 HIGH | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
| CVE-2026-42792 | 6.3 MEDIUM | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-55737 | 5.1 MEDIUM | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts e |
| CVE-2026-47078 | 4.8 MEDIUM | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass |
No comments yet