Junglewise Threat Intelligence

CVE-2026-42790: Erlang OTP certificate validation bypass in public_key module

CVE-2026-42790 · Severity: info · CVSS 7.6 · Published 2026-05-27

Technologies: Erlang Public Key, Erlang OTP. Vendors: Erlang.

Executive brief

Erlang OTP is a popular development platform used to build scalable, high-availability systems. A flaw in its security library allows a restricted certificate authority to issue fraudulent certificates that appear valid to Erlang-based applications. An attacker could use this to impersonate legitimate websites or services, potentially leading to intercepted communications or the theft of sensitive data.

Technical details

A vulnerability exists in the Erlang OTP public_key library (specifically the pubkey_cert and public_key modules) where two flaws combine to bypass DNS nameConstraints. First, pubkey_cert:validate_names/6 only validates Subject Alternative Name (SAN) entries against nameConstraints; a certificate without a SAN extension bypasses these checks entirely. Second, public_key:pkix_verify_hostname/3 incorrectly falls back to the subject CommonName (CN) when no SAN is present, even when using strict HTTPS matching. An attacker with a subordinate CA restricted by DNS nameConstraints can issue a CN-only leaf certificate for an out-of-scope domain that an OTP TLS client will trust. This affects stock ssl:connect configurations using verify_peer and the canonical HTTPS hostname matcher.

Affected products

  • Erlang OTP 19.3 before 26.2.5.21, 27.3.4.12, 28.5.0.1, 29.0.1
  • Erlang public_key 1.4 before 1.15.1.7, 1.17.1.3, 1.20.3.1, 1.21.1

Timeline

  • 2026-05-05: other: Fixes authored in Erlang OTP repository
  • 2026-05-27: advisory: CVE-2026-42790 published by Erlang Ecosystem Foundation

References

Related threats