Exposición de Erlang

Programming languages
101
score de exposición
2073
sitios usan
1
en explotación
2
críticos
Análisis Vexday

Erlang apresenta um volume relativamente pequeno de CVEs catalogadas, mas os indicadores de risco são expressivos: a taxa de exploração ativa está 7,7 vezes acima da média geral do catálogo CISA KEV, sinalizando que vulnerabilidades nessa tecnologia tendem a ser alvos concretos, não apenas teóricos. Chama atenção o CVE-2025-32433, classificado como crítico e com escore EPSS de 0,9767 — indicando altíssima probabilidade de exploração ativa —, o que o torna prioridade imediata de remediação para qualquer ambiente que execute Erlang. O tipo de falha mais recorrente, CWE-295 (validação imprópria de certificados), sugere fragilidades estruturais no tratamento de TLS/SSL, com potencial impacto em confidencialidade e autenticidade de comunicações. O fato de 14 das 29 CVEs terem surgido nos últimos 90 dias reforça a necessidade de monitoramento contínuo e ciclos curtos de patching para esta tecnologia.

CVEs

59 resultados
CVE-2026-70409MEDIUMeldap does not bound the port component of a referral URL before integer conversionEPSS 0.4%CVE-2026-59696MEDIUMuri_string does not bound the port component of a URI before integer conversionEPSS 0.4%CVE-2026-70405MEDIUMsnmp BER INTEGER decoder applies no size limit to attacker-supplied integer fieldsEPSS 0.4%CVE-2026-54890HIGHBEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingEPSS 0.4%CVE-2026-58227HIGHTLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainEPSS 0.4%CVE-2026-71380HIGHhttpd applies no timeout while receiving a request body, parking a worker on a stalled clientEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2026-55951HIGHhttpc memory exhaustion via unbounded response header accumulationEPSS 0.4%CVE-2026-74994MEDIUMinets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_authEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2026-48859MEDIUMSSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumerationEPSS 0.4%CVE-2026-32147MEDIUMSFTP chroot bypass via path traversal in SSH_FXP_FSETSTATEPSS 0.4%CVE-2026-71562MEDIUMhttpc does not bound server-supplied numeric header values before integer conversionEPSS 0.3%CVE-2026-42790HIGHnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationEPSS 0.3%CVE-2026-48856HIGHhttpc leaks Authorization header to cross-origin redirect targetsEPSS 0.3%CVE-2026-54886MEDIUMSSH SFTP server denial of service via extended channel data infinite loopEPSS 0.3%CVE-2026-42789HIGHNon-CA certificate accepted as intermediate issuer in public_key path validationEPSS 0.3%CVE-2026-74835HIGHinets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body ReceptionEPSS 0.3%