Vulnerabilidades en Erlang
62 resultadosAnálisis Vexday
Erlang apresenta 29 vulnerabilidades catalogadas sem nenhuma sob exploração ativa, mas com 17 divulgadas nos últimos 90 dias sinalizando atividade recente de descoberta. A ausência de vulnerabilidades críticas (CVSS) e a fraqueza dominante em CWE-400 (controle inadequado de recursos) sugerem risco moderado, recomendando monitoramento contínuo e atualização regular em vez de ação imediata.
CVE-2026-42789HIGHNon-CA certificate accepted as intermediate issuer in public_key path validationEPSS 0.3%CVE-2026-73276HIGHinets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping iEPSS 0.3%CVE-2026-74835HIGHinets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body ReceptionEPSS 0.3%CVE-2026-66357HIGHinets,httpd:HTTP Request Smuggling via obs-fold Header ContinuationEPSS 0.3%CVE-2026-59251HIGHDenial of service via exponential certificate policy tree growth in path validationEPSS 0.3%CVE-2026-42791MEDIUMOCSP responder certificate validity period not checked in public_keyEPSS 0.3%CVE-2026-73812HIGHinets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-LengthEPSS 0.3%CVE-2025-4748MEDIUMAbsolute path traversal in zip:unzip/1,2EPSS 0.3%CVE-2026-55737MEDIUMHeap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoderEPSS 0.3%CVE-2026-48855LOWSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is ConfiguredEPSS 0.3%CVE-2026-28810MEDIUMPredictable DNS Transaction IDs Enable Cache Poisoning in Built-in ResolverEPSS 0.3%CVE-2024-53846MEDIUMssl fails to validate incorrect extened key usageEPSS 0.3%CVE-2026-53422LOWSFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured rootEPSS 0.3%CVE-2026-65634HIGHSuperlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoderEPSS 0.3%CVE-2026-54887MEDIUMDTLS server cookie bypass during startup window due to empty initial cookie secretEPSS 0.2%CVE-2026-48858MEDIUMftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksEPSS 0.2%CVE-2026-55953CRITICALTLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationEPSS 0.2%CVE-2026-32144HIGHOCSP designated-responder authorization bypass via missing signature verificationEPSS 0.2%CVE-2026-48860HIGHDistribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_distEPSS 0.2%CVE-2026-47078MEDIUMRelative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypassEPSS 0.1%