CVE-2026-42790
- EPSS 0.34%
- Veröffentlicht 27.05.2026 15:09:01
- Zuletzt bearbeitet 18.09.2026 13:18:22
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA...
CVE-2026-42791
- EPSS 0.32%
- Veröffentlicht 27.05.2026 12:23:13
- Zuletzt bearbeitet 24.07.2026 15:17:18
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in pubkey_ocsp:verify_response/...
CVE-2026-42789
- EPSS 0.33%
- Veröffentlicht 27.05.2026 12:23:06
- Zuletzt bearbeitet 28.09.2026 16:17:14
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/src/pubkey_c...
CVE-2026-32147
- EPSS 0.35%
- Veröffentlicht 21.04.2026 12:01:20
- Zuletzt bearbeitet 24.07.2026 15:17:16
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside the configured chroot directory. The SFTP daemon (s...
CVE-2026-28808
- EPSS 0.54%
- Veröffentlicht 07.04.2026 12:28:16
- Zuletzt bearbeitet 08.09.2026 14:17:21
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_...
CVE-2026-32144
- EPSS 0.2%
- Veröffentlicht 07.04.2026 12:28:00
- Zuletzt bearbeitet 24.07.2026 15:17:16
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 doe...
CVE-2026-28810
- EPSS 0.27%
- Veröffentlicht 07.04.2026 07:50:11
- Zuletzt bearbeitet 24.07.2026 15:17:15
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries ...
CVE-2026-23941
- EPSS 0.53%
- Veröffentlicht 13.03.2026 09:11:58
- Zuletzt bearbeitet 24.07.2026 15:17:14
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl a...
CVE-2026-23943
- EPSS 0.64%
- Veröffentlicht 13.03.2026 09:11:57
- Zuletzt bearbeitet 24.07.2026 15:17:14
Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflate...
CVE-2026-23942
- EPSS 0.36%
- Veröffentlicht 13.03.2026 09:11:56
- Zuletzt bearbeitet 24.07.2026 15:17:14
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines s...