Exposição de Erlang

Programming languages
101
score de exposição
2.073
sites usam
1
em exploração
2
críticos
Análise Vexday

Erlang apresenta um volume relativamente pequeno de CVEs catalogadas, mas os indicadores de risco são expressivos: a taxa de exploração ativa está 7,7 vezes acima da média geral do catálogo CISA KEV, sinalizando que vulnerabilidades nessa tecnologia tendem a ser alvos concretos, não apenas teóricos. Chama atenção o CVE-2025-32433, classificado como crítico e com escore EPSS de 0,9767 — indicando altíssima probabilidade de exploração ativa —, o que o torna prioridade imediata de remediação para qualquer ambiente que execute Erlang. O tipo de falha mais recorrente, CWE-295 (validação imprópria de certificados), sugere fragilidades estruturais no tratamento de TLS/SSL, com potencial impacto em confidencialidade e autenticidade de comunicações. O fato de 14 das 29 CVEs terem surgido nos últimos 90 dias reforça a necessidade de monitoramento contínuo e ciclos curtos de patching para esta tecnologia.

CVEs

59 resultados
CVE-2025-32433CRITICALErlang/OTP SSH Vulnerable to Pre-Authentication RCEEPSS 98.8%KEVCVE-2026-59250HIGHMegaco flex scanner buffer overflow via oversized property parm nameEPSS 0.8%CVE-2026-69664HIGHhttpd parks a request worker indefinitely on a malformed chunk size sent after the headersEPSS 0.7%CVE-2026-55950HIGHDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsEPSS 0.7%CVE-2026-73270HIGHhttpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystemsEPSS 0.7%CVE-2026-23943MEDIUMPre-auth SSH DoS via unbounded zlib inflateEPSS 0.6%CVE-2026-66835HIGHhttpd mod_auth directory protection bypassed by a doubled slash in the request pathEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-28808HIGHScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)EPSS 0.6%CVE-2026-70399HIGHhttpd does not enforce the documented default max_clients connection limitEPSS 0.5%CVE-2025-46712LOWErlang/OTP SSH Has Strict KEX ViolationsEPSS 0.5%CVE-2026-49759HIGHStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashEPSS 0.5%CVE-2025-26618HIGHSSH SFTP packet size not verified properly in Erlang OTPEPSS 0.5%CVE-2026-75538HIGHA Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated PeerEPSS 0.5%CVE-2026-55952HIGHTLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionEPSS 0.5%CVE-2026-21620LOWTFTP Path TraversalEPSS 0.5%CVE-2025-30211HIGHKEX init error results with excessive memory usageEPSS 0.5%CVE-2026-23941HIGHRequest smuggling via first-wins Content-Length parsing in inets httpdEPSS 0.5%CVE-2026-42792MEDIUMepmd permanent DoS via EMFILE on accept(2) in ertsEPSS 0.4%CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%