Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

erlang — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting erlang. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Erlang is primarily used for building highly available, distributed systems and real-time applications like messaging platforms and telecom infrastructure. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation flaws and insecure deserialization. The platform's lightweight processes and fault-tolerance features provide inherent security benefits, though misconfigurations can still lead to breaches. Notable incidents include vulnerabilities in the Cowboy web server and OTP components, which have allowed attackers to execute arbitrary code or bypass authentication. Despite these issues, the language's design emphasizes reliability and concurrent processing, making it a preferred choice for systems requiring high uptime and scalability.

Found 42 results / 42 Clear Filters
Top products by erlang: otp
CVE ID Title CVSS Severity Published
CVE-2026-54890 BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding — OTP CWE-191 8.2 High 2026-07-27
CVE-2026-59251 Denial of service via exponential certificate policy tree growth in path validation — OTP CWE-770 8.7 High 2026-07-27
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name — OTP CWE-120 8.3 High 2026-07-27
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication — OTP CWE-757 9.1 Critical 2026-07-27
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder — OTP CWE-195 5.1 Medium 2026-07-27
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass — OTP CWE-23 4.8 Medium 2026-07-27
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts — OTP CWE-755 6.3 Medium 2026-07-27
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain — OTP CWE-674 8.7 High 2026-07-27
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl — OTP CWE-924 6.3 Medium 2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions — OTP CWE-367 8.7 High 2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop — OTP CWE-835 5.3 Medium 2026-07-02
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension — OTP CWE-1284 8.2 High 2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret — OTP CWE-1394 6.3 Medium 2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root — OTP CWE-204 2.3 Low 2026-07-02
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets — OTP CWE-601 7.1 High 2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist — OTP CWE-1025 7.5 High 2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured — OTP CWE-200 2.3 Low 2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks — OTP CWE-918 6.3 Medium 2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration — OTP CWE-208 6.3 Medium 2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash — OTP CWE-121 8.8 High 2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer — OTP CWE-121 6.9 Medium 2026-06-10
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification — OTP CWE-295 7.6 High 2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key — OTP CWE-295 6.3 Medium 2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation — OTP CWE-295 7.0 High 2026-05-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT — OTP CWE-22 5.3 Medium 2026-04-21
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) — OTP CWE-863 8.3 High 2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification — OTP CWE-295 7.6 High 2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver — OTP CWE-340 6.3 Medium 2026-04-07
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd — OTP CWE-444 7.0 High 2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate — OTP CWE-409 6.9 Medium 2026-03-13

This page lists every published CVE security advisory associated with erlang. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.