erlang
29 known vulnerabilities affecting erlang products.
Products
erlang\/otp 29
erlang\/ssl 8
erlang\/ssh 7
erts 4
erlang\/inets 4
erlang\/public_key 2
erl_interface 1
ftp 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-28808 | Medium | 0.6% | 9.8 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unaut… | |
| CVE-2026-49759 | Medium | 0.5% | 8.2 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows a… | |
| CVE-2026-55952 | Medium | 0.5% | 7.5 | The Erlang/OTP ssl application does not validate that the PSK identity list and … | |
| CVE-2026-23941 | Medium | 0.5% | 9.4 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab… | |
| CVE-2026-42792 | Medium | 0.4% | 7.5 | Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (ep… | |
| CVE-2026-54890 | Medium | 0.4% | 7.5 | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (e… | |
| CVE-2026-58227 | Medium | 0.4% | 7.5 | The Erlang/OTP ssl application does not detect cycles when reconstructing an inc… | |
| CVE-2026-42790 | Medium | 0.3% | 8.1 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_c… | |
| CVE-2026-59251 | Medium | 0.3% | 7.5 | Allocation of resources without limits in Erlang/OTP public_key certificate path… | |
| CVE-2026-55737 | Medium | 0.3% | 7.5 | Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erl… | |
| CVE-2026-55953 | Medium | 0.2% | 7.4 | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that th… | |
| CVE-2026-32144 | Medium | 0.2% | 7.4 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o… | |
| CVE-2026-55950 | Low | 0.7% | 5.9 | Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ss… | |
| CVE-2026-23943 | Low | 0.6% | 5.3 | Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in … | |
| CVE-2026-23942 | Low | 0.4% | 5.4 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v… | |
| CVE-2026-32147 | Low | 0.4% | 4.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v… | |
| CVE-2026-48859 | Low | 0.4% | 5.3 | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_opt… | |
| CVE-2026-48856 | Low | 0.3% | 6.5 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module… | |
| CVE-2026-54886 | Low | 0.3% | 4.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang O… | |
| CVE-2026-42789 | Low | 0.3% | 4.8 | Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP… | |
| CVE-2026-42791 | Low | 0.3% | 3.7 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o… | |
| CVE-2026-48855 | Low | 0.3% | 6.5 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erla… | |
| CVE-2026-28810 | Low | 0.3% | 3.7 | Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP ker… | |
| CVE-2026-53422 | Low | 0.3% | 4.3 | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd modul… | |
| CVE-2026-54887 | Low | 0.2% | 4.8 | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) a… | |
| CVE-2026-48858 | Low | 0.2% | 6.5 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal… | |
| CVE-2026-48860 | Low | 0.2% | 6.5 | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_… | |
| CVE-2026-49760 | Low | 0.1% | 5.5 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows S… | |
| CVE-2026-54891 | Low | 0.1% | 3.7 | Improper Enforcement of Message Integrity During Transmission in a Communication… |