Technology · Erlang
Erlang OTP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 47 vulnerabilities in Erlang OTP: 0 in the last 7 days and 27 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-75538, was published on 1 September 2026.
- Last 7 days
- 0
- Last 90 days
- 27
- Critical, all time
- 3
- Exploited in the wild
- 1
About Erlang OTP
A collection of middleware, libraries, and design principles for the Erlang programming language.
Latest Erlang OTP vulnerabilities
- CVE-2026-75538: Erlang/OTP signed integer overflow in inet TCP driver packet parsinginfoCVSS 8.2EPSS 0.9%
- CVE-2026-74994: OTP inets httpd mod_auth directory namespace collapseinfoCVSS 6EPSS 0.6%
- CVE-2026-74835: Erlang OTP inets HTTP server body-size limit bypass in chunked requestsinfoCVSS 8.7EPSS 0.6%
- CVE-2026-73812: Erlang inets HTTP request smuggling via Transfer-Encoding and Content-LengthinfoCVSS 8.3EPSS 0.5%
- CVE-2026-73276: Erlang OTP inets HTTP request smuggling via header whitespaceinfoCVSS 8.3EPSS 0.6%
- CVE-2026-73270: Erlang/OTP inets httpd auth bypass via case sensitivityinfoCVSS 8.2EPSS 0.9%
- CVE-2026-71562: Erlang/OTP inets httpc unbounded numeric header conversion denial of serviceinfoCVSS 6.3EPSS 0.6%
- CVE-2026-71380: Erlang/OTP inets httpd denial of service via stalled request bodyinfoCVSS 8.7EPSS 0.7%
- CVE-2026-70409: Erlang/OTP eldap unbound port integer conversion denial of serviceinfoCVSS 6.3EPSS 0.6%
- CVE-2026-70405: Erlang/OTP snmp BER INTEGER decoder denial of serviceinfoCVSS 6.3EPSS 0.7%
- CVE-2026-70399: Erlang OTP inets httpd resource exhaustion via unlimited connectionsinfoCVSS 8.7EPSS 0.9%
- CVE-2026-66835: Erlang/OTP inets httpd path equivalence authentication bypassinfoCVSS 8.2EPSS 1.0%
- CVE-2026-66357: Erlang httpd HTTP request smuggling via obs-fold header continuationinfoCVSS 8.3EPSS 0.6%
- CVE-2026-59696: Erlang/OTP stdlib URI parser denial of service via long portinfoCVSS 6.9EPSS 0.7%
- CVE-2026-55951: Erlang/OTP httpc memory exhaustion via unbounded response headersinfoCVSS 8.2EPSS 0.7%
- CVE-2026-59251: Erlang OTP denial of service in public_key certificate path validationinfoCVSS 8.7
- CVE-2026-59250: Erlang OTP buffer overflow in Megaco flex scannerinfoCVSS 8.3
- CVE-2026-55953: Erlang OTP authentication bypass in SSL TLS 1.2 clientinfoCVSS 9.1
- CVE-2026-55737: Erlang OTP out-of-bounds write in erts ETF decoderinfoCVSS 5.1
- CVE-2026-54890: Erlang OTP denial of service via integer underflow in ETF decoderinfoCVSS 8.2
- CVE-2026-47078: Erlang OTP path traversal in stdlib zip moduleinfoCVSS 4.8
- CVE-2026-55952: Erlang OTP denial of service in SSL TLS 1.3 session ticket handlinginfoCVSS 8.2
- CVE-2026-55950: Erlang OTP race condition in dtls_packet_demuxinfoCVSS 8.7
- CVE-2026-54891: Erlang OTP plaintext injection in TLS client handshakeinfoCVSS 6.3
- CVE-2026-54887: Erlang OTP predictable DTLS cookie computation in ssl libraryinfoCVSS 6.3
Most severe Erlang OTP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-32433: Erlang Erlang/OTP authentication bypass in SSH Servercriticalexploited in the wildCVSS 10EPSS 47.1%
- CVE-2026-28808: Erlang OTP incorrect authorization in inets mod_authcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23941: Erlang OTP HTTP Request Smuggling in inets httpdcriticalCVSS 9.4EPSS 0.0%
- CVE-2026-32144: Erlang OTP auth bypass in OCSP responder validationhighCVSS 7.4EPSS 0.2%
- CVE-2026-23942: Erlang OTP path traversal in ssh_sftpd root directory validationmediumCVSS 5.4EPSS 0.0%
- CVE-2026-23943: Erlang OTP SSH denial of service via zlib compression bombmediumCVSS 5.3EPSS 0.1%
- CVE-2026-32147: Erlang OTP path traversal in ssh_sftpd modulemediumCVSS 4.3EPSS 0.0%
- CVE-2026-28810: Erlang OTP DNS cache poisoning in inet_res modulelowCVSS 3.7EPSS 0.3%
- CVE-2026-55953: Erlang OTP authentication bypass in SSL TLS 1.2 clientinfoCVSS 9.1
- CVE-2026-49759: Erlang OTP stack buffer overflow in SCTP error parsing in inet_drvinfoCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 15 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/otp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Erlang OTP vulnerabilities", https://junglewise.ai/threats/technologies/otp, 26 September 2026.