Junglewise Threat Intelligence

CVE-2026-42791: Erlang OTP improper certificate validation in public_key OCSP module

CVE-2026-42791 · Severity: info · CVSS 6.3 · Published 2026-05-27

Technologies: Erlang Public Key, Erlang OTP. Vendors: Erlang.

Executive brief

A vulnerability in Erlang/OTP's security library allows the system to accept expired security credentials when checking if a digital certificate is still valid. This could allow a malicious server to trick a user's application into accepting a revoked or untrustworthy connection. In some cases, this may lead to an authentication bypass where unauthorized users gain access using revoked credentials.

Technical details

An improper certificate validation vulnerability exists in the Erlang/OTP public_key application, specifically within the pubkey_ocsp:verify_response/5 and pubkey_ocsp:is_authorized_responder/3 functions. The implementation fails to check the notBefore and notAfter validity periods of OCSP responder certificates. An attacker possessing the private key of an expired CA-designated OCSP responder certificate can forge OCSP responses that the library accepts as valid. This allows a malicious server to present a revoked TLS certificate alongside a forged 'good' OCSP staple, or potentially bypass server-side client certificate authentication. The issue is fixed in OTP versions 27.3.4.12, 28.5.0.1, and 29.0.1.

Affected products

  • Erlang OTP 27.0 before 27.3.4.12, 28.5.0.1, 29.0.1
  • Erlang public_key 1.16 before 1.17.1.3, 1.20.3.1, 1.21.1

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats