Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

erlang — Vulnerabilities & Security Advisories 61

Browse all 61 CVE security advisories affecting erlang. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Erlang is primarily used for building highly available, distributed systems and real-time applications like messaging platforms and telecom infrastructure. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and insecure deserialization. The platform's lightweight processes and fault-tolerance features provide inherent security benefits, though misconfigurations can still lead to breaches. Notable incidents include vulnerabilities in the Cowboy web server and OTP components, which have allowed attackers to execute arbitrary code or bypass authentication. Despite these issues, the language's design emphasizes reliability and concurrent processing, making it a preferred choice for systems requiring high uptime and scalability.

Top products by erlang: otp
CVE ID Title CVSS Severity Published
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension — OTP CWE-1284 8.2 High 2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret — OTP CWE-1394 6.3 Medium 2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root — OTP CWE-204 2.3 Low 2026-07-02
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets — OTP CWE-601 7.1 High 2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured — OTP CWE-200 2.3 Low 2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist — OTP CWE-1025 7.5 High 2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks — OTP CWE-918 6.3 Medium 2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration — OTP CWE-208 6.3 Medium 2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash — OTP CWE-121 8.8 High 2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer — OTP CWE-121 6.9 Medium 2026-06-10
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification — OTP CWE-295 7.6 High 2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key — OTP CWE-295 6.3 Medium 2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation — OTP CWE-295 7.0 High 2026-05-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT — OTP CWE-22 5.3 Medium 2026-04-21
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) — OTP CWE-863 8.3 High 2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification — OTP CWE-295 7.6 High 2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver — OTP CWE-340 6.3 Medium 2026-04-07
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd — OTP CWE-444 7.0 High 2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate — OTP CWE-409 6.9 Medium 2026-03-13
CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd — OTP CWE-22 5.3 Medium 2026-03-13
CVE-2026-21620 TFTP Path Traversal — OTP CWE-23 2.3 Low 2026-02-20
CVE-2025-48041 SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles — OTP CWE-770 7.1 High 2025-09-11
CVE-2025-48040 Malicious Key Exchange Messages may Lead to Excessive Resource Consumption — OTP CWE-400 6.9 Medium 2025-09-11
CVE-2025-48039 Unverified Paths can Cause Excessive Use of System Resources — OTP CWE-770 5.3 Medium 2025-09-11
CVE-2025-48038 Unverified File Handles can Cause Excessive Use of System Resources — OTP CWE-770 5.3 Medium 2025-09-11
CVE-2025-4748 Absolute path traversal in zip:unzip/1,2 — OTP CWE-22 4.8 Medium 2025-06-16
CVE-2025-46712 Erlang/OTP SSH Has Strict KEX Violations — otp CWE-440 3.7 Low 2025-05-08
CVE-2025-32433 Erlang/OTP SSH Vulnerable to Pre-Authentication RCE — otp CWE-306 10.0 Critical 2025-04-16
CVE-2025-30211 KEX init error results with excessive memory usage — otp CWE-789 7.5 High 2025-03-28
CVE-2025-26618 SSH SFTP packet size not verified properly in Erlang OTP — otp CWE-789 5.9 - 2025-02-20

This page lists every published CVE security advisory associated with erlang. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.