Erlang / OTP
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65634 | Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder | HIGH | 8.2 | Sep 22, 2026 |
| CVE-2026-68956 | SSH daemon allocates unbounded idle session channels, bypassing max_channels | HIGH | 7.1 | Sep 22, 2026 |
| CVE-2026-89422 | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension | CRITICAL | 9.3 | Sep 22, 2026 |
| CVE-2026-69664 | httpd parks a request worker indefinitely on a malformed chunk size sent after the headers | HIGH | 8.7 | Sep 1, 2026 |
| CVE-2026-70409 | eldap does not bound the port component of a referral URL before integer conversion | MEDIUM | 6.3 | Sep 1, 2026 |
| CVE-2026-70405 | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields | MEDIUM | 6.3 | Sep 1, 2026 |
| CVE-2026-66835 | httpd mod_auth directory protection bypassed by a doubled slash in the request path | HIGH | 8.2 | Sep 1, 2026 |
| CVE-2026-73270 | httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems | HIGH | 8.2 | Sep 1, 2026 |
| CVE-2026-75538 | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer | HIGH | 8.2 | Sep 1, 2026 |
| CVE-2026-74994 | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth | MEDIUM | 6.0 | Sep 1, 2026 |
| CVE-2026-74835 | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception | HIGH | 8.7 | Sep 1, 2026 |
| CVE-2026-73812 | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length | HIGH | 8.3 | Sep 1, 2026 |
| CVE-2026-73276 | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i | HIGH | 8.3 | Sep 1, 2026 |
| CVE-2026-66357 | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation | HIGH | 8.3 | Sep 1, 2026 |
| CVE-2026-59696 | uri_string does not bound the port component of a URI before integer conversion | MEDIUM | 6.9 | Sep 1, 2026 |
| CVE-2026-55951 | httpc memory exhaustion via unbounded response header accumulation | HIGH | 8.2 | Sep 1, 2026 |
| CVE-2026-71380 | httpd applies no timeout while receiving a request body, parking a worker on a stalled client | HIGH | 8.7 | Sep 1, 2026 |
| CVE-2026-71562 | httpc does not bound server-supplied numeric header values before integer conversion | MEDIUM | 6.3 | Sep 1, 2026 |
| CVE-2026-70399 | httpd does not enforce the documented default max_clients connection limit | HIGH | 8.7 | Sep 1, 2026 |
| CVE-2026-54890 | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding | HIGH | 8.2 | Jul 27, 2026 |
| CVE-2026-59251 | Denial of service via exponential certificate policy tree growth in path validation | HIGH | 8.7 | Jul 27, 2026 |
| CVE-2026-59250 | Megaco flex scanner buffer overflow via oversized property parm name | HIGH | 8.3 | Jul 27, 2026 |
| CVE-2026-55953 | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication | CRITICAL | 9.1 | Jul 27, 2026 |
| CVE-2026-55737 | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder | MEDIUM | 5.1 | Jul 27, 2026 |
| CVE-2026-47078 | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass | MEDIUM | 4.8 | Jul 27, 2026 |
Showing 1 to 25 of 56 CVEs