erlang
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting erlang.
- CVE-2026-65634Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder
- CVE-2026-68956SSH daemon allocates unbounded idle session channels, bypassing max_channels
- CVE-2026-89422TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
- CVE-2026-69664httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
- CVE-2026-70409eldap does not bound the port component of a referral URL before integer conversion
- CVE-2026-70405snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
- CVE-2026-66835httpd mod_auth directory protection bypassed by a doubled slash in the request path
- CVE-2026-73270httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
- CVE-2026-75538A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
- CVE-2026-74994inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
- CVE-2026-74835inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
- CVE-2026-73812inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
- CVE-2026-73276inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
- CVE-2026-66357inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
- CVE-2026-59696uri_string does not bound the port component of a URI before integer conversion