Executive brief
Erlang/OTP is a popular development platform used to build scalable, high-availability systems, including SSH servers. A flaw in its SSH module allows unauthorized individuals to determine which usernames are valid on a server by measuring how long the system takes to respond to login attempts. This information can be used to facilitate more targeted password-guessing attacks or to map out internal user accounts.
Technical details
An observable timing discrepancy exists in the Erlang/OTP ssh_auth and ssh_options modules when the SSH daemon is configured with 'user_passwords' or 'password' options. For valid usernames, the server performs a PBKDF2-SHA256 computation with 600,000 iterations (taking approximately 300ms), whereas it returns immediately (0ms) for invalid usernames. This side-channel allows an unauthenticated remote attacker to enumerate valid usernames in a single attempt per name. The issue is fixed in OTP 29.0.2 (ssh 6.0.1) by introducing a fake PBKDF2 computation for invalid users to ensure consistent timing. Systems using the 'pwdfun' configuration are not affected.
Affected products
- Erlang/OTP ssh (OTP) from 6.0 before 6.0.1
- Erlang/OTP OTP from 29.0 before 29.0.2
Timeline
- 2026-06-03: patched: Fix committed to Erlang/OTP repository
- 2026-06-10: disclosed: Vulnerability disclosed by Erlang Ecosystem Foundation
- 2026-06-10: advisory: GHSA-3w6p-vwhf-wvp4 published