Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

erlang — Vulnerabilities & Security Advisories 61

Browse all 61 CVE security advisories affecting erlang. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Erlang is primarily used for building highly available, distributed systems and real-time applications like messaging platforms and telecom infrastructure. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and insecure deserialization. The platform's lightweight processes and fault-tolerance features provide inherent security benefits, though misconfigurations can still lead to breaches. Notable incidents include vulnerabilities in the Cowboy web server and OTP components, which have allowed attackers to execute arbitrary code or bypass authentication. Despite these issues, the language's design emphasizes reliability and concurrent processing, making it a preferred choice for systems requiring high uptime and scalability.

Top products by erlang: otp
CVE ID Title CVSS Severity Published
CVE-2026-65634 Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder — OTP CWE-407 8.2 High 2026-09-22
CVE-2026-68956 SSH daemon allocates unbounded idle session channels, bypassing max_channels — OTP CWE-770 7.1 High 2026-09-22
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension — OTP CWE-322 9.3 Critical 2026-09-22
CVE-2026-69664 httpd parks a request worker indefinitely on a malformed chunk size sent after the headers — OTP CWE-772 8.7 High 2026-09-01
CVE-2026-70409 eldap does not bound the port component of a referral URL before integer conversion — OTP CWE-1284 6.3 Medium 2026-09-01
CVE-2026-70405 snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields — OTP CWE-1284 6.3 Medium 2026-09-01
CVE-2026-66835 httpd mod_auth directory protection bypassed by a doubled slash in the request path — OTP CWE-50 8.2 High 2026-09-01
CVE-2026-73270 httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems — OTP CWE-178 8.2 High 2026-09-01
CVE-2026-75538 A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer — OTP CWE-190 8.2 High 2026-09-01
CVE-2026-74994 inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth — OTP CWE-863 6.0 Medium 2026-09-01
CVE-2026-74835 inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception — OTP CWE-770 8.7 High 2026-09-01
CVE-2026-73812 inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length — OTP CWE-444 8.3 High 2026-09-01
CVE-2026-73276 inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i — OTP CWE-444 8.3 High 2026-09-01
CVE-2026-66357 inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation — OTP CWE-444 8.3 High 2026-09-01
CVE-2026-59696 uri_string does not bound the port component of a URI before integer conversion — OTP CWE-1284 6.9 Medium 2026-09-01
CVE-2026-55951 httpc memory exhaustion via unbounded response header accumulation — OTP CWE-770 8.2 High 2026-09-01
CVE-2026-71380 httpd applies no timeout while receiving a request body, parking a worker on a stalled client — OTP CWE-772 8.7 High 2026-09-01
CVE-2026-71562 httpc does not bound server-supplied numeric header values before integer conversion — OTP CWE-1284 6.3 Medium 2026-09-01
CVE-2026-70399 httpd does not enforce the documented default max_clients connection limit — OTP CWE-770 8.7 High 2026-09-01
CVE-2026-54890 BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding — OTP CWE-191 8.2 High 2026-07-27
CVE-2026-59251 Denial of service via exponential certificate policy tree growth in path validation — OTP CWE-770 8.7 High 2026-07-27
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name — OTP CWE-120 8.3 High 2026-07-27
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication — OTP CWE-757 9.1 Critical 2026-07-27
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder — OTP CWE-195 5.1 Medium 2026-07-27
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass — OTP CWE-23 4.8 Medium 2026-07-27
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts — OTP CWE-755 6.3 Medium 2026-07-27
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain — OTP CWE-674 8.7 High 2026-07-27
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl — OTP CWE-924 6.3 Medium 2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions — OTP CWE-367 8.7 High 2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop — OTP CWE-835 5.3 Medium 2026-07-02

This page lists every published CVE security advisory associated with erlang. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.