Junglewise Threat Intelligence

CVE-2026-53422: Erlang OTP path enumeration in ssh_sftpd REALPATH handler

CVE-2026-53422 · Severity: info · CVSS 2.3 · Published 2026-07-02

Technologies: Erlang OTP. Vendors: Erlang.

Executive brief

A vulnerability in the Erlang/OTP SFTP server component allows authenticated users to discover the existence of files and directories outside of their assigned folder. While attackers cannot read or modify these files, they can map out the server's internal file structure, which could be used to plan more advanced attacks. This issue only affects systems where the SFTP 'root' option is used for security isolation.

Technical details

The SSH_FXP_REALPATH handler in the ssh_sftpd module fails to properly canonicalize paths before performing root directory validation. Specifically, the handler calls relate_file_name/3 with Canonicalize=false, allowing '..' components to bypass the is_within_root/2 check. These un-canonicalized paths are subsequently processed by resolve_symlinks/2, which can traverse above the configured root. An authenticated attacker can send crafted REALPATH requests; the server returns different error codes (SSH_FXP_NAME vs SSH_FX_NO_SUCH_FILE) depending on whether a path exists, creating a side-channel oracle for filesystem enumeration. The issue is fixed in OTP versions 29.0.3, 28.5.0.3, and 27.3.4.14.

Affected products

  • Erlang OTP 17.0 to 27.3.4.13, 28.5.0.2, 29.0.2
  • Erlang ssh 3.0.1 to 5.2.11.8, 5.5.2.1, 6.0.1

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed

References