Executive brief
Erlang/OTP's eldap library, used for LDAP directory service integration, contains a flaw in parsing LDAP referral URLs. A malicious or compromised LDAP server can craft a referral with an extremely long port number that causes the application to spend hundreds of milliseconds performing arbitrary-precision arithmetic, degrading availability. The attack requires an application to process server-supplied referral URLs, which is not done automatically by eldap itself.
Technical details
The vulnerability is an improper input validation flaw (CWE-1284) in the eldap:parse_port/2 function, which passes the port substring directly to list_to_integer/1 without length bounds. Although list_to_integer/1 is documented to accept integers of any size, a syntactically valid port consisting of up to roughly 1.26 million digits will successfully convert and consume hundreds of milliseconds per referral due to arbitrary-precision arithmetic. The surrounding try-catch only rejects parsing failures, not oversized inputs. Attack vector is network-based; an attacker must compromise or control an LDAP server that the application queries. Exploitation requires the application to explicitly pass a server-supplied referral string to eldap:parse_ldap_url/1, since eldap does not parse referrals automatically. Patches are available in OTP 27.3.4.17+, 28.5.0.6+, and 29.0.6+.
Affected products
- Erlang OTP 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, 29.0 before 29.0.6
- Erlang eldap 1.0.3 before 1.2.14.2, 1.2.15 before 1.2.16.1, 1.3 before 1.3.1
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Patches released in OTP 27.3.4.17, 28.5.0.6, and 29.0.6