{"schema_version":1,"title":"Erlang OTP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 50 vulnerabilities in Erlang OTP: 3 in the last 7 days and 30 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-89422, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/otp","json_url":"https://junglewise.ai/threats/technologies/otp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/otp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":50,"critical":3,"exploited":1,"last_7_days":3,"last_30_days":18,"last_90_days":30,"last_365_days":46},"latest":[{"cve":"CVE-2026-89422","epss":0.0064,"slug":"cve-2026-89422-key-exchange-without-entity-authentication-vulnerability-in","title":"Erlang/OTP ssl TLS 1.3 server authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-22T09:17:05.54+00:00","url":"https://junglewise.ai/threats/cve-2026-89422-key-exchange-without-entity-authentication-vulnerability-in"},{"cve":"CVE-2026-68956","epss":0.0066,"slug":"cve-2026-68956-allocation-of-resources-without-limits-or-throttling","title":"Erlang/OTP SSH unbounded session channel allocation denial of service","severity":"info","exploited":false,"published_at":"2026-09-22T09:17:05.313+00:00","url":"https://junglewise.ai/threats/cve-2026-68956-allocation-of-resources-without-limits-or-throttling"},{"cve":"CVE-2026-65634","epss":0.0042,"slug":"cve-2026-65634-inefficient-algorithmic-complexity-in-the-erlang-otp-asn1-object","title":"Erlang OTP asn1 OBJECT IDENTIFIER decoder algorithmic complexity denial of service","severity":"info","exploited":false,"published_at":"2026-09-22T09:17:05.09+00:00","url":"https://junglewise.ai/threats/cve-2026-65634-inefficient-algorithmic-complexity-in-the-erlang-otp-asn1-object"},{"cve":"CVE-2026-75538","cvss":8.2,"epss":0.0085,"slug":"cve-2026-75538-erlang-otp-signed-integer-overflow-in-inet-tcp-driver-packet","title":"Erlang/OTP signed integer overflow in inet TCP driver packet parsing","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:26.853+00:00","url":"https://junglewise.ai/threats/cve-2026-75538-erlang-otp-signed-integer-overflow-in-inet-tcp-driver-packet"},{"cve":"CVE-2026-74994","cvss":6,"epss":0.0063,"slug":"cve-2026-74994-otp-inets-httpd-mod-auth-directory-namespace-collapse","title":"OTP inets httpd mod_auth directory namespace collapse","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.927+00:00","url":"https://junglewise.ai/threats/cve-2026-74994-otp-inets-httpd-mod-auth-directory-namespace-collapse"},{"cve":"CVE-2026-74835","cvss":8.7,"epss":0.0058,"slug":"cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked","title":"Erlang OTP inets HTTP server body-size limit bypass in chunked requests","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.73+00:00","url":"https://junglewise.ai/threats/cve-2026-74835-erlang-otp-inets-http-server-body-size-limit-bypass-in-chunked"},{"cve":"CVE-2026-73812","cvss":8.3,"epss":0.0052,"slug":"cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and","title":"Erlang inets HTTP request smuggling via Transfer-Encoding and Content-Length","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.54+00:00","url":"https://junglewise.ai/threats/cve-2026-73812-erlang-inets-http-request-smuggling-via-transfer-encoding-and"},{"cve":"CVE-2026-73276","cvss":8.3,"epss":0.0058,"slug":"cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace","title":"Erlang OTP inets HTTP request smuggling via header whitespace","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.367+00:00","url":"https://junglewise.ai/threats/cve-2026-73276-erlang-otp-inets-http-request-smuggling-via-header-whitespace"},{"cve":"CVE-2026-73270","cvss":8.2,"epss":0.0093,"slug":"cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity","title":"Erlang/OTP inets httpd auth bypass via case sensitivity","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:25.103+00:00","url":"https://junglewise.ai/threats/cve-2026-73270-erlang-otp-inets-httpd-auth-bypass-via-case-sensitivity"},{"cve":"CVE-2026-71562","cvss":6.3,"epss":0.0058,"slug":"cve-2026-71562-erlang-otp-inets-httpc-unbounded-numeric-header-conversion-denial","title":"Erlang/OTP inets httpc unbounded numeric header conversion denial of service","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.883+00:00","url":"https://junglewise.ai/threats/cve-2026-71562-erlang-otp-inets-httpc-unbounded-numeric-header-conversion-denial"},{"cve":"CVE-2026-71380","cvss":8.7,"epss":0.0067,"slug":"cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body","title":"Erlang/OTP inets httpd denial of service via stalled request body","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.637+00:00","url":"https://junglewise.ai/threats/cve-2026-71380-erlang-otp-inets-httpd-denial-of-service-via-stalled-request-body"},{"cve":"CVE-2026-70409","cvss":6.3,"epss":0.0058,"slug":"cve-2026-70409-erlang-otp-eldap-unbound-port-integer-conversion-denial-of","title":"Erlang/OTP eldap unbound port integer conversion denial of service","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.427+00:00","url":"https://junglewise.ai/threats/cve-2026-70409-erlang-otp-eldap-unbound-port-integer-conversion-denial-of"},{"cve":"CVE-2026-70405","cvss":6.3,"epss":0.0071,"slug":"cve-2026-70405-erlang-otp-snmp-ber-integer-decoder-denial-of-service","title":"Erlang/OTP snmp BER INTEGER decoder denial of service","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:24.193+00:00","url":"https://junglewise.ai/threats/cve-2026-70405-erlang-otp-snmp-ber-integer-decoder-denial-of-service"},{"cve":"CVE-2026-70399","cvss":8.7,"epss":0.0093,"slug":"cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited","title":"Erlang OTP inets httpd resource exhaustion via unlimited connections","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.947+00:00","url":"https://junglewise.ai/threats/cve-2026-70399-erlang-otp-inets-httpd-resource-exhaustion-via-unlimited"},{"cve":"CVE-2026-66835","cvss":8.2,"epss":0.0097,"slug":"cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass","title":"Erlang/OTP inets httpd path equivalence authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.433+00:00","url":"https://junglewise.ai/threats/cve-2026-66835-erlang-otp-inets-httpd-path-equivalence-authentication-bypass"},{"cve":"CVE-2026-66357","cvss":8.3,"epss":0.0058,"slug":"cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header","title":"Erlang httpd HTTP request smuggling via obs-fold header continuation","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:23.047+00:00","url":"https://junglewise.ai/threats/cve-2026-66357-erlang-httpd-http-request-smuggling-via-obs-fold-header"},{"cve":"CVE-2026-59696","cvss":6.9,"epss":0.0071,"slug":"cve-2026-59696-erlang-otp-stdlib-uri-parser-denial-of-service-via-long-port","title":"Erlang/OTP stdlib URI parser denial of service via long port","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:22.25+00:00","url":"https://junglewise.ai/threats/cve-2026-59696-erlang-otp-stdlib-uri-parser-denial-of-service-via-long-port"},{"cve":"CVE-2026-55951","cvss":8.2,"epss":0.0069,"slug":"cve-2026-55951-erlang-otp-httpc-memory-exhaustion-via-unbounded-response-headers","title":"Erlang/OTP httpc memory exhaustion via unbounded response headers","severity":"info","exploited":false,"published_at":"2026-09-01T15:17:20.78+00:00","url":"https://junglewise.ai/threats/cve-2026-55951-erlang-otp-httpc-memory-exhaustion-via-unbounded-response-headers"},{"cve":"CVE-2026-59251","cvss":8.7,"slug":"cve-2026-59251-erlang-otp-denial-of-service-in-public-key-certificate-path","title":"Erlang OTP denial of service in public_key certificate path validation","severity":"info","exploited":false,"published_at":"2026-07-27T16:18:03.517+00:00","url":"https://junglewise.ai/threats/cve-2026-59251-erlang-otp-denial-of-service-in-public-key-certificate-path"},{"cve":"CVE-2026-59250","cvss":8.3,"slug":"cve-2026-59250-erlang-otp-buffer-overflow-in-megaco-flex-scanner","title":"Erlang OTP buffer overflow in Megaco flex scanner","severity":"info","exploited":false,"published_at":"2026-07-27T16:18:03.33+00:00","url":"https://junglewise.ai/threats/cve-2026-59250-erlang-otp-buffer-overflow-in-megaco-flex-scanner"},{"cve":"CVE-2026-55953","cvss":9.1,"slug":"cve-2026-55953-erlang-otp-authentication-bypass-in-ssl-tls-1-2-client","title":"Erlang OTP authentication bypass in SSL TLS 1.2 client","severity":"info","exploited":false,"published_at":"2026-07-27T16:17:49.5+00:00","url":"https://junglewise.ai/threats/cve-2026-55953-erlang-otp-authentication-bypass-in-ssl-tls-1-2-client"},{"cve":"CVE-2026-55737","cvss":5.1,"slug":"cve-2026-55737-erlang-otp-out-of-bounds-write-in-erts-etf-decoder","title":"Erlang OTP out-of-bounds write in erts ETF decoder","severity":"info","exploited":false,"published_at":"2026-07-27T16:17:48.847+00:00","url":"https://junglewise.ai/threats/cve-2026-55737-erlang-otp-out-of-bounds-write-in-erts-etf-decoder"},{"cve":"CVE-2026-54890","cvss":8.2,"slug":"cve-2026-54890-erlang-otp-denial-of-service-via-integer-underflow-in-etf-decoder","title":"Erlang OTP denial of service via integer underflow in ETF decoder","severity":"info","exploited":false,"published_at":"2026-07-27T16:17:41.437+00:00","url":"https://junglewise.ai/threats/cve-2026-54890-erlang-otp-denial-of-service-via-integer-underflow-in-etf-decoder"},{"cve":"CVE-2026-47078","cvss":4.8,"slug":"cve-2026-47078-erlang-otp-path-traversal-in-stdlib-zip-module","title":"Erlang OTP path traversal in stdlib zip module","severity":"info","exploited":false,"published_at":"2026-07-27T16:17:07.643+00:00","url":"https://junglewise.ai/threats/cve-2026-47078-erlang-otp-path-traversal-in-stdlib-zip-module"},{"cve":"CVE-2026-55952","cvss":8.2,"slug":"cve-2026-55952-erlang-otp-denial-of-service-in-ssl-tls-1-3-session-ticket","title":"Erlang OTP denial of service in SSL TLS 1.3 session ticket handling","severity":"info","exploited":false,"published_at":"2026-07-02T17:17:03.067+00:00","url":"https://junglewise.ai/threats/cve-2026-55952-erlang-otp-denial-of-service-in-ssl-tls-1-3-session-ticket"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":15},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":3}],"related":[{"name":"Erlang Inets","slug":"inets","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/inets"},{"name":"Erlang Ash","slug":"ash","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ash"},{"name":"Erlang Ssl","slug":"ssl","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ssl"},{"name":"Erlang public key","slug":"public-key","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/public-key"},{"name":"Erlang ERTS","slug":"erts","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/erts"}],"technology":{"hub":true,"name":"Erlang OTP","slug":"otp","vendor":{"name":"Erlang","slug":"erlang","url":"https://junglewise.ai/threats/vendors/erlang"},"aliases":["erlang-otp"],"category":"library","homepage":"https://www.erlang.org/","repo_url":"https://github.com/erlang/otp","description":"A collection of middleware, libraries, and design principles for the Erlang programming language.","url":"https://junglewise.ai/threats/technologies/otp"},"most_severe":[{"cve":"CVE-2025-32433","cvss":10,"epss":0.4707,"slug":"cve-2025-32433-erlang-erlang-otp-authentication-bypass-in-ssh-server","title":"Erlang Erlang/OTP authentication bypass in SSH Server","severity":"critical","exploited":true,"published_at":"2025-06-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-32433-erlang-erlang-otp-authentication-bypass-in-ssh-server"},{"cve":"CVE-2026-28808","cvss":9.8,"epss":0.005,"slug":"cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth","title":"Erlang OTP incorrect authorization in inets mod_auth","severity":"critical","exploited":false,"published_at":"2026-04-07T13:16:46.32+00:00","url":"https://junglewise.ai/threats/cve-2026-28808-erlang-otp-incorrect-authorization-in-inets-mod-auth"},{"cve":"CVE-2026-23941","cvss":9.4,"epss":0.0003,"slug":"cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd","title":"Erlang OTP HTTP Request Smuggling in inets httpd","severity":"critical","exploited":false,"published_at":"2026-03-13T19:54:15.237+00:00","url":"https://junglewise.ai/threats/cve-2026-23941-erlang-otp-http-request-smuggling-in-inets-httpd"},{"cve":"CVE-2026-32144","cvss":7.4,"epss":0.0021,"slug":"cve-2026-32144-erlang-otp-auth-bypass-in-ocsp-responder-validation","title":"Erlang OTP auth bypass in OCSP responder validation","severity":"high","exploited":false,"published_at":"2026-04-07T13:16:46.57+00:00","url":"https://junglewise.ai/threats/cve-2026-32144-erlang-otp-auth-bypass-in-ocsp-responder-validation"},{"cve":"CVE-2026-23942","cvss":5.4,"epss":0.0003,"slug":"cve-2026-23942-erlang-otp-path-traversal-in-ssh-sftpd-root-directory-validation","title":"Erlang OTP path traversal in ssh_sftpd root directory validation","severity":"medium","exploited":false,"published_at":"2026-03-13T19:54:15.52+00:00","url":"https://junglewise.ai/threats/cve-2026-23942-erlang-otp-path-traversal-in-ssh-sftpd-root-directory-validation"},{"cve":"CVE-2026-23943","cvss":5.3,"epss":0.0008,"slug":"cve-2026-23943-erlang-otp-ssh-denial-of-service-via-zlib-compression-bomb","title":"Erlang OTP SSH denial of service via zlib compression bomb","severity":"medium","exploited":false,"published_at":"2026-03-13T19:54:15.783+00:00","url":"https://junglewise.ai/threats/cve-2026-23943-erlang-otp-ssh-denial-of-service-via-zlib-compression-bomb"},{"cve":"CVE-2026-32147","cvss":4.3,"epss":0.0002,"slug":"cve-2026-32147-erlang-otp-path-traversal-in-ssh-sftpd-module","title":"Erlang OTP path traversal in ssh_sftpd module","severity":"medium","exploited":false,"published_at":"2026-04-21T12:15:58.8+00:00","url":"https://junglewise.ai/threats/cve-2026-32147-erlang-otp-path-traversal-in-ssh-sftpd-module"},{"cve":"CVE-2026-28810","cvss":3.7,"epss":0.0027,"slug":"cve-2026-28810-erlang-otp-dns-cache-poisoning-in-inet-res-module","title":"Erlang OTP DNS cache poisoning in inet_res module","severity":"low","exploited":false,"published_at":"2026-04-07T09:16:20.473+00:00","url":"https://junglewise.ai/threats/cve-2026-28810-erlang-otp-dns-cache-poisoning-in-inet-res-module"},{"cve":"CVE-2026-55953","cvss":9.1,"slug":"cve-2026-55953-erlang-otp-authentication-bypass-in-ssl-tls-1-2-client","title":"Erlang OTP authentication bypass in SSL TLS 1.2 client","severity":"info","exploited":false,"published_at":"2026-07-27T16:17:49.5+00:00","url":"https://junglewise.ai/threats/cve-2026-55953-erlang-otp-authentication-bypass-in-ssl-tls-1-2-client"},{"cve":"CVE-2026-49759","cvss":8.8,"slug":"cve-2026-49759-erlang-otp-stack-buffer-overflow-in-sctp-error-parsing-in-inet","title":"Erlang OTP stack buffer overflow in SCTP error parsing in inet_drv","severity":"info","exploited":false,"published_at":"2026-06-10T16:17:12.797+00:00","url":"https://junglewise.ai/threats/cve-2026-49759-erlang-otp-stack-buffer-overflow-in-sctp-error-parsing-in-inet"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}