Junglewise Threat Intelligence

CVE-2026-32144: Erlang OTP auth bypass in OCSP responder validation

CVE-2026-32144 · Severity: high · CVSS 7.4 · Published 2026-04-07

Technologies: Erlang Ssl, Erlang Public Key, Erlang OTP. Vendors: Erlang.

Executive brief

A security flaw in Erlang's core networking libraries could allow attackers to bypass certificate revocation checks. This affects applications using SSL/TLS with OCSP stapling, potentially allowing a user to connect to a malicious or compromised server that is using a revoked security certificate. This could lead to the interception of sensitive data or unauthorized access to communications.

Technical details

The OCSP response validation in Erlang's 'public_key:pkix_ocsp_validate/5' function fails to verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. The implementation only checks for a matching issuer name and the 'OCSPSigning' extended key usage (EKU). An attacker capable of intercepting or controlling OCSP responses can provide a self-signed certificate with matching metadata to forge responses, effectively marking revoked certificates as valid. This affects SSL/TLS clients using OCSP stapling and applications directly calling the affected API. Patches are available in OTP versions 28.4.2 and 27.3.4.10.

Affected products

  • Erlang OTP 27.0 to 28.4.2, 27.3.4.10
  • Erlang public_key 1.16 to 1.20.3, 1.17.1.2
  • Erlang ssl 11.2 to 11.5.4, 11.2.12.7

Timeline

  • 2026-04-07: advisory: Initial publication of CVE-2026-32144
  • 2026-04-07: disclosed

References