erlang records
46 published records for vendor erlang.
Researcher profile
- Entered KEV
- 1 · 2.2%
- Weaponized
- 2 · 4.3%
- Pre-auth RCE
- 2
- With a fix record
- 93.5%
- Median publish → KEV
- 54 days
Recurring classes
- CWE-295 Improper Certificate Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-863 Incorrect Authorization2
- CWE-121 Stack-based Buffer Overflow2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-32433Weaponized | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Critical10.0 | KEV | 98.8% | Apr 16, 2025 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.3% | Dec 18, 2023 |
41Plan | CVE-2020-13802No exploit | Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.erlang · rebar3 · CWE-78 | Critical9.8 | — | 6.8% | Sep 2, 2020 |
39Monitor | CVE-2016-10253No exploit | An issue was discovered in Erlang/OTP 18.x.erlang · erlang\/otp · CWE-119 | Critical9.8 | — | 1.5% | Mar 18, 2017 |
39Monitor | CVE-2022-37026No exploit | In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certerlang · erlang\/otp | Critical9.8 | — | 1.5% | Sep 21, 2022 |
36Monitor | CVE-2019-1000014No exploit | Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Paerlang · rebar3 | High8.8 | — | 1.8% | Feb 4, 2019 |
36Monitor | CVE-2026-55953No exploit | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationerlang · erlang\/otp · CWE-757 | Critical9.1 | — | 0.4% | Jul 27, 2026 |
35Monitor | CVE-2026-49759No exploit | Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crasherlang · erlang\/otp · CWE-121 | High8.8 | — | 0.9% | Jun 10, 2026 |
34Monitor | CVE-2026-55950No exploit | DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessionserlang · erlang\/otp · CWE-367 | High8.7 | — | 0.7% | Jul 2, 2026 |
34Monitor | CVE-2026-58227No exploit | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainerlang · erlang\/otp · CWE-674 | High8.7 | — | 0.7% | Jul 27, 2026 |
34Monitor | CVE-2026-59251No exploit | Denial of service via exponential certificate policy tree growth in path validationerlang · erlang\/otp · CWE-770 | High8.7 | — | 0.5% | Jul 27, 2026 |
33Monitor | CVE-2026-28808No exploit | ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)erlang · erlang\/inets · CWE-863 | High8.3 | — | 0.8% | Apr 7, 2026 |
32Monitor | CVE-2011-0766No exploit | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14erlang · crypto · CWE-310 | High7.8 | — | 3.1% | May 31, 2011 |
32Monitor | CVE-2026-55952No exploit | TLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionerlang · erlang\/otp · CWE-1284 | High8.2 | — | 0.9% | Jul 2, 2026 |
32Monitor | CVE-2026-54890No exploit | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingerlang · erlang\/otp · CWE-191 | High8.2 | — | 0.7% | Jul 27, 2026 |
31Monitor | CVE-2020-25623No exploit | Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.erlang · erlang\/otp · CWE-22 | High7.5 | — | 3.2% | Oct 2, 2020 |
31Monitor | CVE-2014-1693No exploit | Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP comerlang · erlang\/otp | High7.5 | — | 2.2% | Dec 8, 2014 |
30Monitor | CVE-2017-1000385Weaponized | The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding.erlang · erlang\/otp · CWE-203 | Medium5.9 | — | 22.1% | Dec 12, 2017 |
30Monitor | CVE-2009-0130No exploit | lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow erlang · erlang · CWE-287 | High7.5 | — | 1.2% | Jan 15, 2009 |
30Monitor | CVE-2020-35733No exploit | An issue was discovered in Erlang/OTP before 23.2.2.erlang · erlang\/otp · CWE-295 | High7.5 | — | 1.2% | Jan 15, 2021 |
30Monitor | CVE-2026-42790No exploit | nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationerlang · erlang\/otp · CWE-295 | High7.6 | — | 0.5% | May 27, 2026 |
30Monitor | CVE-2026-48860No exploit | Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_disterlang · erlang\/otp · CWE-863 | High7.5 | — | 0.4% | Jun 10, 2026 |
30Monitor | CVE-2026-32144No exploit | OCSP designated-responder authorization bypass via missing signature verificationerlang · erlang\/otp · CWE-295 | High7.6 | — | 0.3% | Apr 7, 2026 |
28Monitor | CVE-2021-29221No exploit | A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.erlang · erlang\/otp · CWE-426 | High7.0 | — | 0.6% | Apr 9, 2021 |
28Monitor | CVE-2026-48856No exploit | httpc leaks Authorization header to cross-origin redirect targetserlang · erlang\/inets · CWE-601 | High7.1 | — | 0.6% | Jun 10, 2026 |
- CVE-2025-32433100Now
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CriticalCVSS 10.0KEVWeaponizedEPSS 99%erlang · erlang\/otpApr 16, 2025
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 93%ssh · sshDec 18, 2023
- CVE-2020-1380241Plan
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
CriticalCVSS 9.8No exploitEPSS 7%erlang · rebar3Sep 2, 2020
- CVE-2016-1025339Monitor
An issue was discovered in Erlang/OTP 18.x.
CriticalCVSS 9.8No exploitEPSS 1%erlang · erlang\/otpMar 18, 2017
- CVE-2022-3702639Monitor
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-cert
CriticalCVSS 9.8No exploitEPSS 1%erlang · erlang\/otpSep 21, 2022
- CVE-2019-100001436Monitor
Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Pa
HighCVSS 8.8No exploitEPSS 2%erlang · rebar3Feb 4, 2019
- CVE-2026-5595336Monitor
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
CriticalCVSS 9.1No exploitEPSS 0%erlang · erlang\/otpJul 27, 2026
- CVE-2026-4975935Monitor
Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash
HighCVSS 8.8No exploitEPSS 1%erlang · erlang\/otpJun 10, 2026
- CVE-2026-5595034Monitor
DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions
HighCVSS 8.7No exploitEPSS 1%erlang · erlang\/otpJul 2, 2026
- CVE-2026-5822734Monitor
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
HighCVSS 8.7No exploitEPSS 1%erlang · erlang\/otpJul 27, 2026
- CVE-2026-5925134Monitor
Denial of service via exponential certificate policy tree growth in path validation
HighCVSS 8.7No exploitEPSS 1%erlang · erlang\/otpJul 27, 2026
- CVE-2026-2880833Monitor
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
HighCVSS 8.3No exploitEPSS 1%erlang · erlang\/inetsApr 7, 2026
- CVE-2011-076632Monitor
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14
HighCVSS 7.8No exploitEPSS 3%erlang · cryptoMay 31, 2011
- CVE-2026-5595232Monitor
TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
HighCVSS 8.2No exploitEPSS 1%erlang · erlang\/otpJul 2, 2026
- CVE-2026-5489032Monitor
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
HighCVSS 8.2No exploitEPSS 1%erlang · erlang\/otpJul 27, 2026
- CVE-2020-2562331Monitor
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.
HighCVSS 7.5No exploitEPSS 3%erlang · erlang\/otpOct 2, 2020
- CVE-2014-169331Monitor
Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP com
HighCVSS 7.5No exploitEPSS 2%erlang · erlang\/otpDec 8, 2014
- CVE-2017-100038530Monitor
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding.
MediumCVSS 5.9WeaponizedEPSS 22%erlang · erlang\/otpDec 12, 2017
- CVE-2009-013030Monitor
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow
HighCVSS 7.5No exploitEPSS 1%erlang · erlangJan 15, 2009
- CVE-2020-3573330Monitor
An issue was discovered in Erlang/OTP before 23.2.2.
HighCVSS 7.5No exploitEPSS 1%erlang · erlang\/otpJan 15, 2021
- CVE-2026-4279030Monitor
nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
HighCVSS 7.6No exploitEPSS 0%erlang · erlang\/otpMay 27, 2026
- CVE-2026-4886030Monitor
Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
HighCVSS 7.5No exploitEPSS 0%erlang · erlang\/otpJun 10, 2026
- CVE-2026-3214430Monitor
OCSP designated-responder authorization bypass via missing signature verification
HighCVSS 7.6No exploitEPSS 0%erlang · erlang\/otpApr 7, 2026
- CVE-2021-2922128Monitor
A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.
HighCVSS 7.0No exploitEPSS 1%erlang · erlang\/otpApr 9, 2021
- CVE-2026-4885628Monitor
httpc leaks Authorization header to cross-origin redirect targets
HighCVSS 7.1No exploitEPSS 1%erlang · erlang\/inetsJun 10, 2026