Junglewise Threat Intelligence

CVE-2026-54891: Erlang OTP plaintext injection in TLS client handshake

CVE-2026-54891 · Severity: info · CVSS 6.3 · Published 2026-07-02

Technologies: Erlang OTP, Erlang Ssl. Vendors: Erlang.

Executive brief

Erlang/OTP is a popular development platform used to build high-concurrency systems like messaging apps and financial switches. A vulnerability in its SSL/TLS library allows a network-positioned attacker to inject unauthenticated data into a secure connection while it is being established. This could result in an application processing malicious or spoofed data as if it came from a trusted server, though the attacker cannot see the encrypted traffic or take full control of the session.

Technical details

The vulnerability exists in the 'tls_gen_connection' module of the Erlang/OTP ssl application. The 'handle_protocol_record/3' function fails to properly reject APPLICATION_DATA records that arrive before the TLS handshake is complete when the endpoint is acting as a client. A network-positioned attacker can send plaintext records during this 'handshake window'; these records are buffered by the stack and delivered to the application as authenticated data once the handshake finishes. While the attacker cannot decrypt the subsequent session or steer the connection, they can perform blind injection of unauthenticated bytes. The issue is mitigated in TLS 1.3 due to a smaller injection window but remains present. Patches are available in OTP versions 29.0.3, 28.5.0.3, and 27.3.4.14.

Affected products

  • Erlang OTP 17.0 before 29.0.3, 28.5.0.3, 27.3.4.14
  • Erlang ssl 5.3.4 before 11.7.3, 11.6.0.3, 11.2.12.10

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed

References