Junglewise Threat Intelligence

CVE-2026-70405: Erlang/OTP snmp BER INTEGER decoder denial of service

CVE-2026-70405 · Severity: info · CVSS 6.3 · Published 2026-09-01

Technologies: Erlang OTP. Vendors: Erlang.

Executive brief

Erlang/OTP's SNMP (Simple Network Management Protocol) service decodes network management messages that contain integers without proper size validation. An attacker can send a specially crafted SNMP message with an extremely large integer field, causing the SNMP decoder to consume excessive CPU and memory while processing the message, degrading availability for legitimate management traffic and operations.

Technical details

The vulnerability is an improper input validation flaw (CWE-1284) in the BER INTEGER decoder of Erlang/OTP's SNMP library. The function snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, allowing arbitrarily large length fields in BER-encoded integers. The vulnerable do_dec_integer_notag/2 function then accumulates the integer value through recursive bit shifts and bitwise operations on progressively larger bignums, resulting in superlinear CPU consumption based on the declared length. The decode occurs before PDU validation, so no authentication or valid SNMP request structure is required—the attacker only needs network reachability to the SNMP service to send a malicious message. A remote, unauthenticated attacker can trigger severe CPU and memory exhaustion, causing denial of service. Patches are available in OTP 27.3.4.17, 28.5.0.6, 29.0.6 and later, and in snmp 5.18.2.1, 5.20.2.2, and 5.20.5 and later.

Affected products

  • Erlang OTP 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, 29.0 before 29.0.6
  • Erlang snmp 4.25.1 before 5.18.2.1, 5.19 before 5.20.2.2, 5.20.3 before 5.20.5

Timeline

  • 2026-09-01: disclosed
  • 2026-09-08: advisory: CVE details published and updated

References

Related threats