Vendor
Erlang vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 59 vulnerabilities in Erlang: 3 in the last 7 days and 31 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-89422, was published on 22 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 3
- Last 90 days
- 31
- Critical, all time
- 4
- Exploited in the wild
- 1
About Erlang
A general-purpose, concurrent, functional programming language and runtime system.
Erlang technologies
Latest Erlang vulnerabilities
- CVE-2026-89422: Erlang/OTP ssl TLS 1.3 server authentication bypassinfoEPSS 0.6%
- CVE-2026-68956: Erlang/OTP SSH unbounded session channel allocation denial of serviceinfoEPSS 0.7%
- CVE-2026-65634: Erlang OTP asn1 OBJECT IDENTIFIER decoder algorithmic complexity denial of serviceinfoEPSS 0.4%
- CVE-2026-75538: Erlang/OTP signed integer overflow in inet TCP driver packet parsinginfoCVSS 8.2EPSS 0.9%
- CVE-2026-74994: OTP inets httpd mod_auth directory namespace collapseinfoCVSS 6EPSS 0.6%
- CVE-2026-74835: Erlang OTP inets HTTP server body-size limit bypass in chunked requestsinfoCVSS 8.7EPSS 0.6%
- CVE-2026-73812: Erlang inets HTTP request smuggling via Transfer-Encoding and Content-LengthinfoCVSS 8.3EPSS 0.5%
- CVE-2026-73276: Erlang OTP inets HTTP request smuggling via header whitespaceinfoCVSS 8.3EPSS 0.6%
- CVE-2026-73270: Erlang/OTP inets httpd auth bypass via case sensitivityinfoCVSS 8.2EPSS 0.9%
- CVE-2026-71562: Erlang/OTP inets httpc unbounded numeric header conversion denial of serviceinfoCVSS 6.3EPSS 0.6%
- CVE-2026-71380: Erlang/OTP inets httpd denial of service via stalled request bodyinfoCVSS 8.7EPSS 0.7%
- CVE-2026-70409: Erlang/OTP eldap unbound port integer conversion denial of serviceinfoCVSS 6.3EPSS 0.6%
- CVE-2026-70405: Erlang/OTP snmp BER INTEGER decoder denial of serviceinfoCVSS 6.3EPSS 0.7%
- CVE-2026-70399: Erlang OTP inets httpd resource exhaustion via unlimited connectionsinfoCVSS 8.7EPSS 0.9%
- CVE-2026-66835: Erlang/OTP inets httpd path equivalence authentication bypassinfoCVSS 8.2EPSS 1.0%
- CVE-2026-66357: Erlang httpd HTTP request smuggling via obs-fold header continuationinfoCVSS 8.3EPSS 0.6%
- CVE-2026-59696: Erlang/OTP stdlib URI parser denial of service via long portinfoCVSS 6.9EPSS 0.7%
- CVE-2026-55951: Erlang/OTP httpc memory exhaustion via unbounded response headersinfoCVSS 8.2EPSS 0.7%
- CVE-2026-49457: erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server…criticalCVSS 9.1EPSS 0.3%
- CVE-2026-59251: Erlang OTP denial of service in public_key certificate path validationinfoCVSS 8.7
- CVE-2026-59250: Erlang OTP buffer overflow in Megaco flex scannerinfoCVSS 8.3
- CVE-2026-55953: Erlang OTP authentication bypass in SSL TLS 1.2 clientinfoCVSS 9.1
- CVE-2026-55737: Erlang OTP out-of-bounds write in erts ETF decoderinfoCVSS 5.1
- CVE-2026-54890: Erlang OTP denial of service via integer underflow in ETF decoderinfoCVSS 8.2
- CVE-2026-47078: Erlang OTP path traversal in stdlib zip moduleinfoCVSS 4.8
Most severe Erlang vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-32433: Erlang Erlang/OTP authentication bypass in SSH Servercriticalexploited in the wildCVSS 10EPSS 47.1%
- CVE-2026-28808: Erlang OTP incorrect authorization in inets mod_authcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23941: Erlang OTP HTTP Request Smuggling in inets httpdcriticalCVSS 9.4EPSS 0.0%
- CVE-2026-49457: erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server…criticalCVSS 9.1EPSS 0.3%
- ex-aws ex_aws_sns signature bypass via untrusted SigningCertURLhighCVSS 8.7
- CVE-2026-34593: Ash Framework Denial of Service via Atom Exhaustion in Module TypehighCVSS 7.5EPSS 0.4%
- CVE-2026-32873: Loop with Unreachable Exit Condition ('Infinite Loop') in ewehighCVSS 7.5
- CVE-2026-32144: Erlang OTP auth bypass in OCSP responder validationhighCVSS 7.4EPSS 0.2%
- CVE-2026-32686: ericmj decimal denial of service via unbounded exponentmediumCVSS 6.9EPSS 0.3%
- CVE-2026-42794: absinthe-graphql absinthe_plug reflected XSS in GraphiQL interfacemediumCVSS 6.1EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 15 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 3 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/erlang.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Erlang vulnerabilities", https://junglewise.ai/threats/vendors/erlang, 27 September 2026.