| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-75538 | vulnerable | vulnerable | vulnerable | vulnerable | An attacker that connects to an open Erlang TCP port that uses the ine ... |
| CVE-2026-74994 | vulnerable | vulnerable | vulnerable | vulnerable | The mod_auth module in OTP's inets httpd server, when configured with ... |
| CVE-2026-74835 | vulnerable | vulnerable | vulnerable | vulnerable | The inets application HTTP server httpd fails to enforce a configured ... |
| CVE-2026-73812 | vulnerable | vulnerable | vulnerable | vulnerable | httpd function check_header/3 rejects duplicate Content-Length (per CV ... |
| CVE-2026-73276 | vulnerable | vulnerable | vulnerable | vulnerable | Gracefulness code ignored cases that should be rejected, resulting in ... |
| CVE-2026-73270 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inet ... |
| CVE-2026-71380 | vulnerable | vulnerable | vulnerable | vulnerable | Missing Release of Resource after Effective Lifetime vulnerability in ... |
| CVE-2026-70409 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Validation of Specified Quantity in Input vulnerability in Er ... |
| CVE-2026-70405 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Validation of Specified Quantity in Input vulnerability in Er ... |
| CVE-2026-70399 | vulnerable | vulnerable | vulnerable | vulnerable | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2026-69664 | vulnerable | vulnerable | vulnerable | vulnerable | Missing Release of Resource after Effective Lifetime vulnerability in ... |
| CVE-2026-66835 | vulnerable | vulnerable | vulnerable | vulnerable | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ... |
| CVE-2026-66357 | vulnerable | vulnerable | vulnerable | vulnerable | httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 7230 \xa7 ... |
| CVE-2026-59696 | vulnerable | vulnerable | vulnerable | vulnerable | Improper Validation of Specified Quantity in Input vulnerability in Er ... |
| CVE-2026-59251 | vulnerable | fixed | fixed | fixed | Allocation of resources without limits in Erlang/OTP public_key certif ... |
| CVE-2026-59250 | vulnerable | fixed | fixed | fixed | Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ... |
| CVE-2026-58227 | vulnerable | fixed | fixed | fixed | The Erlang/OTP ssl application does not detect cycles when reconstruct ... |
| CVE-2026-55953 | vulnerable | fixed | fixed | fixed | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not veri ... |
| CVE-2026-55952 | vulnerable | fixed | fixed | fixed | The Erlang/OTP ssl application does not validate that the PSK identity ... |
| CVE-2026-55951 | vulnerable | vulnerable | vulnerable | vulnerable | The Erlang/OTP httpc HTTP client does not enforce a limit on the total ... |
| CVE-2026-55950 | vulnerable | fixed | fixed | fixed | Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erl ... |
| CVE-2026-55737 | vulnerable | fixed | fixed | fixed | Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ... |
| CVE-2026-54891 | vulnerable | fixed | fixed | fixed | Improper Enforcement of Message Integrity During Transmission in a Com ... |
| CVE-2026-54890 | vulnerable | fixed | fixed | fixed | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ... |
| CVE-2026-54887 | vulnerable | fixed | fixed | fixed | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS ... |
| CVE-2026-54886 | vulnerable | fixed | fixed | fixed | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ... |
| CVE-2026-53422 | vulnerable | fixed | fixed | fixed | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_s ... |
| CVE-2026-49760 | vulnerable | fixed | fixed | fixed | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface ... |
| CVE-2026-49759 | vulnerable | fixed | fixed | fixed | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv ... |
| CVE-2026-48860 | vulnerable | fixed | fixed | fixed | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ... |
| CVE-2026-48858 | vulnerable | fixed | fixed | fixed | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ft ... |
| CVE-2026-48856 | vulnerable | fixed | fixed | fixed | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_respo ... |
| CVE-2026-48855 | vulnerable | fixed | fixed | fixed | Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ... |
| CVE-2026-47078 | vulnerable | fixed | fixed | fixed | Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ... |
| CVE-2026-42792 | vulnerable | fixed | fixed | fixed | Improper Handling of Exceptional Conditions vulnerability in Erlang OT ... |
| CVE-2026-42790 | vulnerable | fixed | fixed | fixed | Improper Certificate Validation vulnerability in Erlang OTP public_key ... |
| CVE-2026-42789 | vulnerable | fixed | fixed | fixed | Improper Following of a Certificate's Chain of Trust vulnerability in ... |
| CVE-2026-32147 | vulnerable (no DSA) | fixed | fixed | fixed | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... |
| CVE-2026-28810 | vulnerable (no DSA) | fixed | fixed | fixed | Generation of Predictable Numbers or Identifiers vulnerability in Erla ... |
| CVE-2026-28808 | vulnerable (no DSA) | fixed | fixed | fixed | Incorrect Authorization vulnerability in Erlang OTP (inets modules) al ... |
| Bug | Description |
|---|
| CVE-2026-48859 | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_aut ... |
| CVE-2026-42791 | Improper Certificate Validation vulnerability in Erlang OTP public_key ... |
| CVE-2026-32144 | Improper Certificate Validation vulnerability in Erlang OTP public_key ... |
| CVE-2026-23943 | Improper Handling of Highly Compressed Data (Compression Bomb) vulnera ... |
| CVE-2026-23942 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... |
| CVE-2026-23941 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling' ... |
| CVE-2026-21620 | Relative Path Traversal, Improper Isolation or Compartmentalization vu ... |
| CVE-2025-48041 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2025-48040 | Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh ... |
| CVE-2025-48039 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2025-48038 | Allocation of Resources Without Limits or Throttling vulnerability in ... |
| CVE-2025-46712 | Erlang/OTP is a set of libraries for the Erlang programming language. ... |
| CVE-2025-32433 | Erlang/OTP is a set of libraries for the Erlang programming language. ... |
| CVE-2025-30211 | Erlang/OTP is a set of libraries for the Erlang programming language. ... |
| CVE-2025-26618 | Erlang is a programming language and runtime system for building massi ... |
| CVE-2025-4748 | Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ... |
| CVE-2024-53846 | OTP is a set of Erlang libraries, which consists of the Erlang runtime ... |
| CVE-2023-48795 | The SSH transport protocol with certain OpenSSH extensions, found in O ... |
| CVE-2022-37026 | In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before ... |
| CVE-2021-29221 | A local privilege escalation vulnerability was discovered in Erlang/OT ... |
| CVE-2020-35733 | An issue was discovered in Erlang/OTP before 23.2.2. The ssl applicati ... |
| CVE-2020-25623 | Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Director ... |
| CVE-2020-12872 | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ... |
| CVE-2017-1000385 | The Erlang otp TLS server answers with different TLS alerts to differe ... |
| CVE-2016-10253 | An issue was discovered in Erlang/OTP 18.x. Erlang's generation of com ... |
| CVE-2015-2774 | Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes w ... |
| CVE-2014-3566 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other prod ... |
| CVE-2014-1693 | Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OT ... |
| CVE-2011-3389 | The SSL protocol, as used in certain configurations in Microsoft Windo ... |
| CVE-2011-0766 | The random number generator in the Crypto application before 2.0.2.2, ... |