CVE-2026-65634
- EPSS 0.25%
- Veröffentlicht 22.09.2026 08:49:24
- Zuletzt bearbeitet 24.09.2026 21:17:20
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:dec_subidentif...
CVE-2026-68956
- EPSS 0.49%
- Veröffentlicht 22.09.2026 08:49:21
- Zuletzt bearbeitet 24.09.2026 21:17:30
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The "session" clause of ssh...
CVE-2026-89422
- EPSS 0.37%
- Veröffentlicht 22.09.2026 08:49:16
- Zuletzt bearbeitet 22.09.2026 19:09:32
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes t...
CVE-2026-69664
- EPSS 0.69%
- Veröffentlicht 01.09.2026 14:59:03
- Zuletzt bearbeitet 22.09.2026 10:17:09
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal numb...
CVE-2026-70409
- EPSS 0.42%
- Veröffentlicht 01.09.2026 14:51:00
- Zuletzt bearbeitet 08.09.2026 01:17:53
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_por...
CVE-2026-70405
- EPSS 0.42%
- Veröffentlicht 01.09.2026 14:50:34
- Zuletzt bearbeitet 08.09.2026 01:17:52
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. snmp_pdus:dec_integer_n...
CVE-2026-66835
- EPSS 0.64%
- Veröffentlicht 01.09.2026 14:49:47
- Zuletzt bearbeitet 08.09.2026 01:17:52
Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the requ...
CVE-2026-73270
- EPSS 0.66%
- Veröffentlicht 01.09.2026 14:48:53
- Zuletzt bearbeitet 08.09.2026 01:17:53
Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is ca...
CVE-2026-75538
- EPSS 0.49%
- Veröffentlicht 01.09.2026 14:48:26
- Zuletzt bearbeitet 08.09.2026 02:17:27
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2...
- EPSS 0.36%
- Veröffentlicht 01.09.2026 14:45:57
- Zuletzt bearbeitet 08.09.2026 02:17:27
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one pr...