Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

otp — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in otp, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation report for the otp product within the open-source software category, focusing on security weakness classifications and tracking. It collects data on known security flaws, ranging from critical remote code execution risks to minor configuration issues, covering the period from the product's initial release through recent updates up to the current year. By reviewing this aggregated information, users can effectively track vendor advisories for the otp software to stay informed about the latest security patches and mitigation strategies. Additionally, analysts can understand specific weakness classes that affect the product, such as input validation errors or cryptographic failures, allowing for better risk assessment. The page also serves as a reference for looking up the product's vulnerability history, enabling developers and security professionals to identify trends, recurring issues, and the overall security posture of the otp implementation over time. This consolidated view helps in prioritizing remediation efforts and ensuring compliance with security standards. The data is sourced from official vendor notifications, public vulnerability databases, and community-reported incidents, ensuring a broad and accurate representation of the threat landscape. Users are encouraged to cross-reference these findings with official documentation for detailed guidance on patching and configuration hardening. This resource is intended for technical audiences responsible for maintaining the integrity and security of systems relying on the otp product.

Vendor: erlang

CVE ID Title CVSS Severity Published
CVE-2026-54890 BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding CWE-191 8.2 High 2026-07-27
CVE-2026-59251 Denial of service via exponential certificate policy tree growth in path validation CWE-770 8.7 High 2026-07-27
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name CWE-120 8.3 High 2026-07-27
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication CWE-757 9.1 Critical 2026-07-27
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder CWE-195 5.1 Medium 2026-07-27
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass CWE-23 4.8 Medium 2026-07-27
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts CWE-755 6.3 Medium 2026-07-27
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain CWE-674 8.7 High 2026-07-27
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl CWE-924 6.3 Medium 2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions CWE-367 8.7 High 2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop CWE-835 5.3 Medium 2026-07-02
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension CWE-1284 8.2 High 2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret CWE-1394 6.3 Medium 2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root CWE-204 2.3 Low 2026-07-02
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets CWE-601 7.1 High 2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist CWE-1025 7.5 High 2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured CWE-200 2.3 Low 2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks CWE-918 6.3 Medium 2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration CWE-208 6.3 Medium 2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash CWE-121 8.8 High 2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer CWE-121 6.9 Medium 2026-06-10
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification CWE-295 7.6 High 2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key CWE-295 6.3 Medium 2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation CWE-295 7.0 High 2026-05-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT CWE-22 5.3 Medium 2026-04-21
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) CWE-863 8.3 High 2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification CWE-295 7.6 High 2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver CWE-340 6.3 Medium 2026-04-07
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd CWE-444 7.0 High 2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate CWE-409 6.9 Medium 2026-03-13

All 42 known CVE vulnerabilities affecting otp with full Chinese analysis, references, and POCs where available.