Executive brief
A vulnerability in the Erlang/OTP built-in DNS resolver could allow an attacker to redirect network traffic to malicious servers. By predicting the identification numbers used for DNS lookups, an attacker can provide fraudulent address information, potentially leading to data theft or service impersonation. This issue primarily affects systems configured to use Erlang's internal resolver rather than the standard operating system resolver.
Technical details
The Erlang/OTP built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and fails to implement source port randomization. Because response validation relies almost exclusively on this predictable ID, it violates RFC 5452 recommendations for mitigating forged DNS answers. An attacker capable of observing a query or predicting the next ID can perform DNS cache poisoning. This vulnerability affects the inet_res and inet_db modules when the application is explicitly configured to use the Erlang resolver instead of the native OS resolver. Patches have been released in OTP versions 28.4.2, 27.3.4.10, and 26.2.5.19.
Affected products
- Erlang OTP 17.0 before 28.4.2, 27.3.4.10, 26.2.5.19
- Erlang Kernel 3.0 before 10.6.2, 10.2.7.4, 9.2.4.11
Timeline
- 2026-03-17: patched: Initial patches committed to GitHub repository
- 2026-04-07: disclosed: Public disclosure of CVE-2026-28810
- 2026-04-07: advisory
References
- https://github.com/
- https://cna.erlef.org/cves/CVE-2026-28810.html
- https://github.com/erlang/otp/commit/36f23c9d2cc54afe83671dd7343596d7972839a5
- https://github.com/erlang/otp/commit/b057a9d995017b1be50d6dc02edd52382f3231b8
- https://github.com/erlang/otp/commit/dd15e8eb03548c5e55e9915f0e91389ec6bad9fd
- https://github.com/erlang/otp/security/advisories/GHSA-v884-5jg5-whj8