Vendor
Erlang/OTP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 5 vulnerabilities in Erlang/OTP: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58227, was published on 27 July 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About Erlang/OTP
Erlang/OTP is an open-source project maintained by the Erlang/OTP team at Ericsson that provides a programming language and runtime system.
Latest Erlang/OTP vulnerabilities
- CVE-2026-58227: Erlang OTP uncontrolled recursion in ssl certificate chain buildinginfoCVSS 8.7
- CVE-2026-49760: Erlang OTP stack overflow in erl_interface ei_s_print_terminfoCVSS 6.9
- CVE-2026-48860: Erlang OTP auth bypass in inet_tls_dist LAN allowlistinfoCVSS 7.5
- CVE-2025-48041: Erlang OTP resource exhaustion in ssh_sftpdinfoCVSS 7.1EPSS 0.2%
- CVE-2025-48038: Erlang OTP resource exhaustion in SFTP server handle processinginfoCVSS 5.3EPSS 0.2%
Most severe Erlang/OTP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-58227: Erlang OTP uncontrolled recursion in ssl certificate chain buildinginfoCVSS 8.7
- CVE-2026-48860: Erlang OTP auth bypass in inet_tls_dist LAN allowlistinfoCVSS 7.5
- CVE-2025-48041: Erlang OTP resource exhaustion in ssh_sftpdinfoCVSS 7.1EPSS 0.2%
- CVE-2026-49760: Erlang OTP stack overflow in erl_interface ei_s_print_terminfoCVSS 6.9
- CVE-2025-48038: Erlang OTP resource exhaustion in SFTP server handle processinginfoCVSS 5.3EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/erlang-otp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Erlang/OTP vulnerabilities", https://junglewise.ai/threats/vendors/erlang-otp, 26 September 2026.