Vulnerabilities in erlang
62 resultsVexday analysis
Erlang apresenta um perfil de risco contido com 6 CVEs catalogadas, das quais apenas 1 está sob exploração ativa (KEV). A principal vulnerabilidade é do tipo CWE-789 (alocação de memória sem limites), com 1 crítica identificada, porém sem publicações recentes nos últimos 90 dias, indicando que o risco atual é derivado de exposições antigas já conhecidas.
CVE-2025-32433CRITICALErlang/OTP SSH Vulnerable to Pre-Authentication RCEEPSS 98.8%KEVCVE-2026-59250HIGHMegaco flex scanner buffer overflow via oversized property parm nameEPSS 1.2%CVE-2026-66835HIGHhttpd mod_auth directory protection bypassed by a doubled slash in the request pathEPSS 1.0%CVE-2026-69664HIGHhttpd parks a request worker indefinitely on a malformed chunk size sent after the headersEPSS 0.9%CVE-2026-73270HIGHhttpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystemsEPSS 0.9%CVE-2026-70399HIGHhttpd does not enforce the documented default max_clients connection limitEPSS 0.9%CVE-2026-55952HIGHTLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionEPSS 0.9%CVE-2026-49759HIGHStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashEPSS 0.9%CVE-2026-75538HIGHA Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated PeerEPSS 0.9%CVE-2026-42792MEDIUMepmd permanent DoS via EMFILE on accept(2) in ertsEPSS 0.8%CVE-2026-28808HIGHScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)EPSS 0.8%CVE-2026-59696MEDIUMuri_string does not bound the port component of a URI before integer conversionEPSS 0.7%CVE-2026-70405MEDIUMsnmp BER INTEGER decoder applies no size limit to attacker-supplied integer fieldsEPSS 0.7%CVE-2026-55951HIGHhttpc memory exhaustion via unbounded response header accumulationEPSS 0.7%CVE-2026-55950HIGHDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsEPSS 0.7%CVE-2026-58227HIGHTLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainEPSS 0.7%CVE-2026-71380HIGHhttpd applies no timeout while receiving a request body, parking a worker on a stalled clientEPSS 0.7%CVE-2026-68956HIGHSSH daemon allocates unbounded idle session channels, bypassing max_channelsEPSS 0.7%CVE-2026-54890HIGHBEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingEPSS 0.7%CVE-2026-23943MEDIUMPre-auth SSH DoS via unbounded zlib inflateEPSS 0.6%