Erlang OTP

20 known vulnerabilities in Erlang OTP, 2 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-32433 CVSS 10.0 critical · actively exploited Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Latest vulnerabilities

  • CVE-2026-89422 CVSS 9.3 critical Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to…
  • CVE-2026-68956 CVSS 7.1 high Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust…
  • CVE-2026-65634 CVSS 8.2 high Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause…
  • CVE-2026-75538 CVSS 8.2 high An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an…
  • CVE-2026-74994 CVSS 6.0 medium The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory…
  • CVE-2026-74835 CVSS 8.7 high The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP…
  • CVE-2026-73812 CVSS 8.3 high httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC…
  • CVE-2026-73276 CVSS 8.3 high Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects…
  • CVE-2026-73270 CVSS 8.2 high Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files…
  • CVE-2026-71562 CVSS 6.3 medium Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server…
  • CVE-2026-71380 CVSS 8.7 high Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to…
  • CVE-2026-70409 CVSS 6.3 medium Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to…
  • CVE-2026-70405 CVSS 6.3 medium Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by…
  • CVE-2026-70399 CVSS 8.7 high Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to…
  • CVE-2026-69664 CVSS 8.7 high Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to…
  • CVE-2026-66835 CVSS 8.2 high Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth…
  • CVE-2026-66357 CVSS 8.3 high httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet…
  • CVE-2026-59696 CVSS 6.9 medium Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by…
  • CVE-2026-55951 CVSS 8.2 high The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The…
  • CVE-2025-32433 CVSS 10.0 critical · actively exploited Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability