Junglewise Threat Intelligence

CVE-2025-48039: Erlang OTP resource exhaustion in SSH SFTP subsystem

CVE-2025-48039 · Severity: info · CVSS 5.3 · Published 2025-09-11

Vendors: Erlang.

Executive brief

A vulnerability in the Erlang SSH library's SFTP module allows a remote user to consume excessive system resources. By sending specially crafted file paths without length limits, an attacker can cause memory exhaustion or resource leaks. This could lead to service slowdowns or crashes on systems running Erlang-based SSH servers.

Technical details

The Erlang OTP SSH daemon's SFTP subsystem (ssh_sftpd.erl) fails to properly throttle or limit the size of file paths provided by clients. An authenticated attacker can exploit this by providing excessively long or unverified paths, leading to uncontrolled resource consumption (CWE-400) and potential resource leaks. The vulnerability is mitigated by a new 'max_path' configuration option, which defaults to 4096 bytes. Exploitation requires the SFTP subsystem to be enabled (which is the default) and the attacker to have valid login credentials. Patches have been released in OTP versions 28.0.3, 27.3.4.3, and 26.2.5.15.

Affected products

  • Erlang OTP ssh (ssh_sftp modules) 17.0 to 28.0.3, 27.3.4.3, 26.2.5.15

Timeline

  • 2025-09-11: advisory: Initial disclosure by Erlang Ecosystem Foundation (EEF)
  • 2025-09-02: patched: Fixes committed to Erlang/OTP repository

References