Junglewise Threat Intelligence

CVE-2026-21620: Erlang OTP path traversal in tftp_file module

CVE-2026-21620 · Severity: info · CVSS 2.3 · Published 2026-02-20

Technologies: Erlang OTP. Vendors: Erlang.

Executive brief

Erlang/OTP is a popular development platform used to build scalable and high-availability systems. A security flaw in its TFTP (Trivial File Transfer Protocol) service could allow an attacker to access or modify files outside of the intended directory. This could lead to the exposure of sensitive system information or the unauthorized modification of files if the TFTP server is exposed to the network.

Technical details

A relative path traversal vulnerability (CWE-23) exists in the tftp_file callback module within Erlang/OTP's tftp and inets applications. The flaw occurs when the TFTP server is started with the {root_dir, Dir} option, failing to properly validate or sanitize file paths provided by the client. A remote attacker with network access to the TFTP port can use '..' sequences to escape the configured root directory and read or write files elsewhere on the filesystem. This affects OTP versions 17.0 through 28.3.1.x and has been patched in versions 28.3.2, 27.3.4.8, and 26.2.5.17.

Affected products

  • Erlang OTP (tftp and inets applications) 17.0 before 28.3.2, 27.3.4.8, and 26.2.5.17

Timeline

  • 2026-02-19: patched: Fixes merged into Erlang/OTP maintenance branches.
  • 2026-02-20: advisory: CVE-2026-21620 published.

References

Related threats