Executive brief
A vulnerability in the Erlang OTP SSH implementation could allow an attacker to crash or slow down services by sending specially crafted network messages. This affects the SFTP and SSH modules used by many applications for secure file transfers and remote management. An exploit could lead to a denial-of-service, preventing legitimate users from accessing the system or its data.
Technical details
An uncontrolled resource consumption vulnerability exists in the Erlang OTP SSH implementation, specifically within the ssh_sftp modules and ssh_sftpd.erl. The flaw is triggered during the SSH key exchange (KEX) process when the server receives a KEX init message containing an excessive number of algorithms or other malicious data. This leads to uncontrolled resource allocation or flooding, potentially resulting in a denial-of-service (DoS). Attackers can exploit this over the network without authentication. Patches have been released in OTP versions 28.0.3, 27.3.4.3, and 26.2.5.15. Workarounds include setting the 'parallel_login' option to false or reducing the 'max_sessions' limit.
Affected products
- Erlang OTP 17.0 to 28.0.3, 27.3.4.3, 26.2.5.15
- Erlang ssh 3.0.1 to 5.3.3, 5.2.11.3, 5.1.4.12
Timeline
- 2025-08-27: patched: Fixes committed to Erlang OTP repository
- 2025-09-11: disclosed: CVE published by Erlang Ecosystem Foundation CNA
References
- https://cna.erlef.org/cves/CVE-2025-48040.html
- https://github.com/erlang/otp/commit/548f1295d86d0803da884db8685cc16d461d0d5a
- https://github.com/erlang/otp/commit/7cd7abb7e19e16b027eaee6a54e1f6fbbe21181a
- https://github.com/erlang/otp/pull/10162
- https://github.com/erlang/otp/security/advisories/GHSA-h7rg-6rjg-4cph
- https://www.erlang.org/doc/system/versions.html