Vulnerabilidades em erlang
62 resultadosAnálise Vexday
Erlang apresenta um perfil de risco contido com 6 CVEs catalogadas, das quais apenas 1 está sob exploração ativa (KEV). A principal vulnerabilidade é do tipo CWE-789 (alocação de memória sem limites), com 1 crítica identificada, porém sem publicações recentes nos últimos 90 dias, indicando que o risco atual é derivado de exposições antigas já conhecidas.
CVE-2025-48040MEDIUMMalicious Key Exchange Messages may Lead to Excessive Resource ConsumptionEPSS 0.4%CVE-2026-70409MEDIUMeldap does not bound the port component of a referral URL before integer conversionEPSS 0.4%CVE-2026-70405MEDIUMsnmp BER INTEGER decoder applies no size limit to attacker-supplied integer fieldsEPSS 0.4%CVE-2026-59696MEDIUMuri_string does not bound the port component of a URI before integer conversionEPSS 0.4%CVE-2026-54890HIGHBEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingEPSS 0.4%CVE-2026-71380HIGHhttpd applies no timeout while receiving a request body, parking a worker on a stalled clientEPSS 0.4%CVE-2026-58227HIGHTLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainEPSS 0.4%CVE-2025-48041HIGHSSH_FXP_OPENDIR may Lead to Exhaustion of File HandlesEPSS 0.4%CVE-2025-48039MEDIUMUnverified Paths can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2025-48038MEDIUMUnverified File Handles can Cause Excessive Use of System ResourcesEPSS 0.4%CVE-2026-55951HIGHhttpc memory exhaustion via unbounded response header accumulationEPSS 0.4%CVE-2026-89422CRITICALTLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extensionEPSS 0.4%CVE-2026-74994MEDIUMinets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_authEPSS 0.4%CVE-2026-23942MEDIUMSFTP root escape via component-agnostic prefix check in ssh_sftpdEPSS 0.4%CVE-2026-48859MEDIUMSSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumerationEPSS 0.4%CVE-2026-32147MEDIUMSFTP chroot bypass via path traversal in SSH_FXP_FSETSTATEPSS 0.4%CVE-2026-71562MEDIUMhttpc does not bound server-supplied numeric header values before integer conversionEPSS 0.3%CVE-2026-42790HIGHnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationEPSS 0.3%CVE-2026-48856HIGHhttpc leaks Authorization header to cross-origin redirect targetsEPSS 0.3%CVE-2026-54886MEDIUMSSH SFTP server denial of service via extended channel data infinite loopEPSS 0.3%