Executive brief
A security flaw in the Erlang/OTP SSL library allows an attacker positioned between a client and server to intercept and modify encrypted communications. By forcing the client to use an 'anonymous' encryption method that was never requested, the attacker can bypass identity checks and certificate validation. This allows the attacker to read sensitive data or inject malicious content into what should be a secure connection.
Technical details
A vulnerability exists in the Erlang/OTP ssl application where the TLS 1.2 (and earlier) and DTLS client-side handshake handler (tls_handshake:hello/5) fails to perform a membership check on the cipher suite returned by the server. An on-path attacker can respond with a ServerHello selecting an anonymous key exchange suite (e.g., TLS_DH_anon_*) that the client did not offer. Because anonymous suites do not require a server certificate, the client's verify_peer and cacerts configurations are bypassed, resulting in a successful handshake with the attacker. This allows for complete Adversary-in-the-Middle (AiTM) capabilities, including reading and modifying application traffic. The issue is fixed in OTP versions 29.0.4, 28.5.0.4, and 27.3.4.15.
Affected products
- Erlang OTP 17.0 to 27.3.4.14, 28.0 to 28.5.0.3, 29.0 to 29.0.3
- Erlang ssl 5.3.4 to 11.2.12.10, 11.6.0.0 to 11.6.0.3, 11.7.0 to 11.7.3
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
References
- https://github.com/
- https://cna.erlef.org/cves/CVE-2026-55953.html
- https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b
- https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c
- https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77
- https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882