PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42789 Erlang CVE debrief

CVE-2026-42789 Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. This affects OTP from 17.0 before 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability is caused by flaws in the pubkey_cert:validate_extensions/7 function in lib/public_key/src/pubkey_cert.erl, which allow a certificate with basicConstraints cA:false and no keyUsage extension to be used as an intermediate issuer in a chain passed to public_key:pkix_path_validation/3. This can lead to certificate chain forgery in TLS or mTLS endpoints using the OTP ssl application

Vendor
Erlang
Product
OTP
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-09-28
Advisory published
2026-05-27
Advisory updated
2026-09-28

Who should care

Defenders responsible for Erlang OTP deployments, especially those using TLS or mTLS, should assess exposure and apply patches to prevent certificate chain forgery. This includes reviewing trust store configurations and monitoring for suspicious certificate activity. Defenders should also perform vulnerability scanning to identify exposed systems and implement compensating controls for exposed systems.

Why it matters

CVE-2026-42789 allows certificate chain forgery in Erlang OTP's public_key, affecting TLS/mTLS endpoints. Defenders should verify exposure, apply patches, and review trust store configurations to prevent impersonation and identity verification bypass.

  • Certificate chain forgery can allow impersonation of arbitrary identities
  • Affected TLS or mTLS endpoints may be vulnerable to identity verification bypass
  • Verification of affected versions and patch application is necessary
  • Remediation requires updating OTP versions and reviewing trust store configurations

Technical summary

The pubkey_cert module in Erlang OTP's public_key does not properly validate certificate chains, allowing a non-CA certificate to be used as an intermediate issuer. This can lead to certificate chain forgery in TLS or mTLS endpoints using the OTP ssl application. The vulnerability is caused by flaws in the pubkey_cert:validate_extensions/7 function in lib/public_key/src/pubkey_cert.erl. The issue affects OTP from OTP 17.0 before OTP 26.2.5.21, OTP 27.3.4.12, OTP 28.5.0.1, and OTP 29.0.1, corresponding to public_key from 0.22 before 1.15.1.7, 1.17.1.3, 1.20.3.1, and 1.21.1.

Defensive priority

Defenders should prioritize verifying affected versions and applying patches due to potential certificate chain forgery risks.

Recommended defensive actions

  • Verify affected OTP versions and apply patches
  • Review and update trust store configurations
  • Monitor for suspicious certificate activity
  • Perform vulnerability scanning to identify exposed systems
  • Implement compensating controls for exposed systems
  • Review and update incident response plans
  • Conduct a thorough risk assessment of affected systems

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. Patches are available from Erlang. The vulnerability allows certificate chain forgery in Erlang OTP's public_key, affecting TLS/mTLS endpoints. Defenders should verify exposure, apply patches, and review trust store configurations to prevent impersonation and identity verification bypass. The issue affects OTP from OTP 17.0 before OTP 26.2.5.21, OTP 27.3.4.12, OTP 28.5.0.1, and OTP 29.0.1, corresponding to public_key from 0.22 before 1.15.1.7, 1.7

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42789 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42789

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42789 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42789

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-42789.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-42789

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.erlang.org/doc/system/versions.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Product

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:39809

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:54757

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.