CVEs we hold for Erlang
Records whose assigning authority named Erlang as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-75538A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an…Erlang OTP
CVE-2026-74994inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_authErlang OTP
CVE-2026-74835inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body ReceptionErlang OTP
CVE-2026-73812inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-LengthErlang OTP
CVE-2026-73276inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping iErlang OTP
CVE-2026-73270httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystemsErlang OTP
CVE-2026-71562httpc does not bound server-supplied numeric header values before integer conversionErlang OTP
CVE-2026-71380httpd applies no timeout while receiving a request body, parking a worker on a stalled clientErlang OTP
CVE-2026-70409eldap does not bound the port component of a referral URL before integer conversionErlang OTP
CVE-2026-70405snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fieldsErlang OTP
CVE-2026-69664httpd parks a request worker indefinitely on a malformed chunk size sent after the headersErlang OTP
CVE-2026-66884Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF…Erlang Ecosystem Foundation oidcc_plug
CVE-2026-66883Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookupErlang Ecosystem Foundation oidcc_plug
CVE-2026-66835httpd mod_auth directory protection bypassed by a doubled slash in the request pathErlang OTP
CVE-2026-59696uri_string does not bound the port component of a URI before integer conversionErlang OTP
CVE-2026-59251Denial of service via exponential certificate policy tree growth in path validationErlang OTP
CVE-2026-58227TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainErlang OTP
CVE-2026-55953TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationErlang OTP
CVE-2026-55952TLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionErlang OTP
CVE-2026-55950DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsErlang OTP
CVE-2026-55737Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoderErlang OTP
CVE-2026-54891Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslErlang OTP
CVE-2026-54890BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingErlang OTP
CVE-2026-54887DTLS server cookie bypass during startup window due to empty initial cookie secretErlang OTP
CVE-2026-53422SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured rootErlang OTP
CVE-2026-49759Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashErlang OTP
CVE-2026-48860Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_distErlang OTP
CVE-2026-48859SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumerationErlang OTP
CVE-2026-48858ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksErlang OTP
CVE-2026-48855SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is ConfiguredErlang OTP
CVE-2026-47078Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypassErlang OTP
CVE-2026-42790nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationErlang OTP
CVE-2026-42789Non-CA certificate accepted as intermediate issuer in public_key path validationErlang OTP
CVE-2026-32144OCSP designated-responder authorization bypass via missing signature verificationErlang OTP
CVE-2026-28808ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)Erlang OTP
61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.