Vulnerabilidades em Erlang
62 resultadosAnálise Vexday
Erlang apresenta 29 vulnerabilidades catalogadas sem nenhuma sob exploração ativa, mas com 17 divulgadas nos últimos 90 dias sinalizando atividade recente de descoberta. A ausência de vulnerabilidades críticas (CVSS) e a fraqueza dominante em CWE-400 (controle inadequado de recursos) sugerem risco moderado, recomendando monitoramento contínuo e atualização regular em vez de ação imediata.
CVE-2025-32433CRITICALErlang/OTP SSH Vulnerable to Pre-Authentication RCEEPSS 98.8%KEVCVE-2026-59250HIGHMegaco flex scanner buffer overflow via oversized property parm nameEPSS 0.8%CVE-2026-69664HIGHhttpd parks a request worker indefinitely on a malformed chunk size sent after the headersEPSS 0.7%CVE-2026-55950HIGHDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionsEPSS 0.7%CVE-2026-73270HIGHhttpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystemsEPSS 0.7%CVE-2026-23943MEDIUMPre-auth SSH DoS via unbounded zlib inflateEPSS 0.6%CVE-2026-66835HIGHhttpd mod_auth directory protection bypassed by a doubled slash in the request pathEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-28808HIGHScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)EPSS 0.6%CVE-2026-70399HIGHhttpd does not enforce the documented default max_clients connection limitEPSS 0.5%CVE-2025-46712LOWErlang/OTP SSH Has Strict KEX ViolationsEPSS 0.5%CVE-2026-49759HIGHStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashEPSS 0.5%CVE-2025-26618HIGHSSH SFTP packet size not verified properly in Erlang OTPEPSS 0.5%CVE-2026-75538HIGHA Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated PeerEPSS 0.5%CVE-2026-55952HIGHTLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionEPSS 0.5%CVE-2026-21620LOWTFTP Path TraversalEPSS 0.5%CVE-2026-68956HIGHSSH daemon allocates unbounded idle session channels, bypassing max_channelsEPSS 0.5%CVE-2025-30211HIGHKEX init error results with excessive memory usageEPSS 0.5%CVE-2026-23941HIGHRequest smuggling via first-wins Content-Length parsing in inets httpdEPSS 0.5%CVE-2026-42792MEDIUMepmd permanent DoS via EMFILE on accept(2) in ertsEPSS 0.4%