Executive brief
A vulnerability in the Erlang/OTP SSL library allows an unauthenticated remote attacker to crash applications using TLS or DTLS. By sending a specially crafted certificate chain that contains circular references, an attacker can cause the system to run out of memory and stop responding. This affects both servers and clients that use Erlang's standard SSL/TLS implementation, potentially leading to a total service outage.
Technical details
The Erlang/OTP 'ssl' application fails to detect cycles or enforce depth limits when reconstructing incomplete peer certificate chains. Specifically, in 'ssl_certificate:handle_incomplete_chain/5', the application uses 'do_certificate_chain/7' to walk issuer relationships. If an attacker provides two mutually cross-signed certificates (e.g., A signs B and B signs A) in an unordered form, the functions recurse indefinitely. This leads to unbounded growth of the call stack and memory exhaustion, ultimately crashing the BEAM node. The attack can be launched by an unauthenticated remote peer during the TLS/DTLS handshake before authentication is completed. Patches are available in OTP versions 29.0.4, 28.5.0.4, and 27.3.4.15.
Affected products
- Erlang OTP (ssl application) 23.2 before 29.0.4, 28.5.0.4, and 27.3.4.15
Timeline
- 2026-07-03: other: Fix authored
- 2026-07-27: advisory: Vulnerability disclosed by Erlang Ecosystem Foundation
References
- https://github.com/
- https://cna.erlef.org/cves/CVE-2026-58227.html
- https://github.com/erlang/otp/commit/0307bff2c72b685c6bd952daaac6bd661c247d62
- https://github.com/erlang/otp/commit/241d43703989fec4b6bf637beaeb366d92dcc4c2
- https://github.com/erlang/otp/commit/7db64720177961e04545681480d691c4be81c54d
- https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw