Vulnerabilidades en erlang

43 resultados
Análisis Vexday

Erlang apresenta um perfil de risco contido com 6 CVEs catalogadas, das quais apenas 1 está sob exploração ativa (KEV). A principal vulnerabilidade é do tipo CWE-789 (alocação de memória sem limites), com 1 crítica identificada, porém sem publicações recentes nos últimos 90 dias, indicando que o risco atual é derivado de exposições antigas já conhecidas.

CVE-2025-32433CRITICALErlang/OTP SSH Vulnerable to Pre-Authentication RCEEPSS 98.6%KEVCVE-2026-59250HIGHMegaco flex scanner buffer overflow via oversized property parm nameEPSS 0.7%CVE-2026-23943MEDIUMPre-auth SSH DoS via unbounded zlib inflateEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-28808HIGHScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)EPSS 0.5%CVE-2026-23941HIGHRequest smuggling via first-wins Content-Length parsing in inets httpdEPSS 0.5%CVE-2026-49759HIGHStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashEPSS 0.5%CVE-2025-46712LOWErlang/OTP SSH Has Strict KEX ViolationsEPSS 0.5%CVE-2026-55952HIGHTLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionEPSS 0.5%CVE-2025-26618HIGHSSH SFTP packet size not verified properly in Erlang OTPEPSS 0.5%CVE-2026-21620LOWTFTP Path TraversalEPSS 0.5%CVE-2025-30211HIGHKEX init error results with excessive memory usageEPSS 0.4%CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%CVE-2026-42792MEDIUMepmd permanent DoS via EMFILE on accept(2) in ertsEPSS 0.4%CVE-2026-55950HIGHDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2026-32147MEDIUMSFTP chroot bypass via path traversal in SSH_FXP_FSETSTATEPSS 0.4%