Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Erlang\/otp HIGH 7.5
CVE-2026-59251

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial …

Fix: 1.17.1.5 / 1.20.3.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-58227

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl…

Fix: 11.2.12.11 / 11.6.0.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.4
CVE-2026-55953

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the su…

Fix: 11.2.12.11 / 11.6.0.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-55737

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang exter…

Fix: 15.2.7.11 / 16.4.0.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-54890

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Ov…

Fix: 15.2.7.11 / 16.4.0.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-42792

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminat…

Fix: 15.2.7.11 / 16.4.0.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-55952

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension…

Fix: 11.2.12.10 / 11.6.0.3+
Fix from $1,950 2026-07-02
Erlang\/otp MEDIUM 5.9
CVE-2026-55950

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacke…

Fix: 11.2.12.10 / 11.6.0.3+
Fix from $1,600 2026-07-02
Erlang\/otp HIGH 8.2
CVE-2026-49759

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a c…

Fix: 15.2.7.9 / 16.4.0.2+
Fix from $1,950 2026-06-10
Erlang\/otp MEDIUM 6.5
CVE-2026-48860

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-ov…

Fix: 11.2.12.9 / 11.6.0.2+
Fix from $1,600 2026-06-10
Erl Interface MEDIUM 5.5
CVE-2026-49760

Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with pr…

Fix: 5.5.2.1 / 5.7.0.1+
Fix from $1,600 2026-06-10
Erlang\/otp MEDIUM 5.3
CVE-2026-48859

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via …

Fix: 6.0.1 / 29.0.2+
Fix from $1,600 2026-06-10
Erlang\/inets MEDIUM 6.5
CVE-2026-48858

Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV r…

Fix: 1.2.3.1 / 1.2.4.1+
Fix from $1,600 2026-06-10
Erlang\/inets MEDIUM 6.5
CVE-2026-48856

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards…

Fix: 9.3.2.6 / 9.6.2.2+
Fix from $1,600 2026-06-10
Erlang\/otp MEDIUM 6.5
CVE-2026-48855

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_REA…

Fix: 5.2.11.8 / 5.5.2.1+
Fix from $1,600 2026-06-10
Erlang\/otp HIGH 8.1
CVE-2026-42790

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via s…

Fix: 26.2.5.21 / 27.3.4.12+
Fix from $1,950 2026-05-27
Erlang\/inets CRITICAL 9.8
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se…

Fix: 9.1.0.6 / 9.3.2.4+
Fix from $2,300 2026-04-07
Erlang\/otp HIGH 7.4
CVE-2026-32144

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via…

Fix: 1.17.1.2 / 1.20.3+
Fix from $1,950 2026-04-07
Erlang\/inets CRITICAL 9.4
CVE-2026-23941

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin…

Fix: 9.1.0.5 / 9.3.2.3+
Fix from $2,300 2026-03-13
Erlang\/otp MEDIUM 5.4
CVE-2026-23942

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. …

Fix: 5.1.4.14 / 5.2.11.6+
Fix from $1,600 2026-03-13
Erlang\/otp MEDIUM 5.3
CVE-2026-23943

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via R…

Fix: 5.1.4.14 / 5.2.11.6+
Fix from $1,600 2026-03-13
Rebar3 HIGH 7.5
CVE-2026-21619

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api module…

Fix: 0.12.1 / 2.3.2+
Fix from $1,950 2026-02-27
Erlang\/otp CRITICAL 9.8
CVE-2022-37026

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification…

Fix: 23.3.4.15 / 24.3.4.2+
Fix from $2,300 2022-09-21
Erlang\/otp HIGH 7.0
CVE-2021-29221

A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an existing installation's direct…

Fix: 23.2.3+
Fix from $1,950 2021-04-09
Erlang\/otp HIGH 7.5
CVE-2020-25623

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary file…

Fix: 22.3.4.6 / 23.1+
Fix from $1,950 2020-10-02
Rebar3 CRITICAL 9.8
CVE-2020-13802EPSS 7%

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

Fix: after 3.13.2
Fix from $2,300 2020-09-02
Erlang\/otp MEDIUM 6.1
CVE-2016-1000107

inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted …

Fix: after 22.1
Fix from $1,600 2019-12-10
Rebar3 HIGH 8.8
CVE-2019-1000014

Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Package mod…

Fix: after 3.7.5
Fix from $1,950 2019-02-04
Erlang\/otp CRITICAL 9.8
CVE-2016-10253

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions…

Patch available
Fix from $2,300 2017-03-18
Erlang\/otp MEDIUM 5.9
CVE-2015-2774

Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attack…

Fix: after 18.0
Fix from $1,600 2016-04-07