Erlang

Erlang/otp

60 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 22.09.2026 08:49:24
  • Zuletzt bearbeitet 24.09.2026 21:17:20

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:dec_subidentif...

  • EPSS 0.49%
  • Veröffentlicht 22.09.2026 08:49:21
  • Zuletzt bearbeitet 24.09.2026 21:17:30

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The "session" clause of ssh...

  • EPSS 0.37%
  • Veröffentlicht 22.09.2026 08:49:16
  • Zuletzt bearbeitet 22.09.2026 19:09:32

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes t...

Medienbericht
  • EPSS 0.69%
  • Veröffentlicht 01.09.2026 14:59:03
  • Zuletzt bearbeitet 22.09.2026 10:17:09

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal numb...

Medienbericht
  • EPSS 0.42%
  • Veröffentlicht 01.09.2026 14:51:00
  • Zuletzt bearbeitet 08.09.2026 01:17:53

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_por...

  • EPSS 0.42%
  • Veröffentlicht 01.09.2026 14:50:34
  • Zuletzt bearbeitet 08.09.2026 01:17:52

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. snmp_pdus:dec_integer_n...

Medienbericht
  • EPSS 0.64%
  • Veröffentlicht 01.09.2026 14:49:47
  • Zuletzt bearbeitet 08.09.2026 01:17:52

Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the requ...

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 01.09.2026 14:48:53
  • Zuletzt bearbeitet 08.09.2026 01:17:53

Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is ca...

Medienbericht
  • EPSS 0.49%
  • Veröffentlicht 01.09.2026 14:48:26
  • Zuletzt bearbeitet 08.09.2026 02:17:27

An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 01.09.2026 14:45:57
  • Zuletzt bearbeitet 08.09.2026 02:17:27

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one pr...