PatchSiren cyber security CVE debrief
CVE-2026-42789 Erlang CVE debrief
CVE-2026-42789 Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. This affects OTP from 17.0 before 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability is caused by flaws in the pubkey_cert:validate_extensions/7 function in lib/public_key/src/pubkey_cert.erl, which allow a certificate with basicConstraints cA:false and no keyUsage extension to be used as an intermediate issuer in a chain passed to public_key:pkix_path_validation/3. This can lead to certificate chain forgery in TLS or mTLS endpoints using the OTP ssl application
- Vendor
- Erlang
- Product
- OTP
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for Erlang OTP deployments, especially those using TLS or mTLS, should assess exposure and apply patches to prevent certificate chain forgery. This includes reviewing trust store configurations and monitoring for suspicious certificate activity. Defenders should also perform vulnerability scanning to identify exposed systems and implement compensating controls for exposed systems.
Why it matters
CVE-2026-42789 allows certificate chain forgery in Erlang OTP's public_key, affecting TLS/mTLS endpoints. Defenders should verify exposure, apply patches, and review trust store configurations to prevent impersonation and identity verification bypass.
- Certificate chain forgery can allow impersonation of arbitrary identities
- Affected TLS or mTLS endpoints may be vulnerable to identity verification bypass
- Verification of affected versions and patch application is necessary
- Remediation requires updating OTP versions and reviewing trust store configurations
Technical summary
The pubkey_cert module in Erlang OTP's public_key does not properly validate certificate chains, allowing a non-CA certificate to be used as an intermediate issuer. This can lead to certificate chain forgery in TLS or mTLS endpoints using the OTP ssl application. The vulnerability is caused by flaws in the pubkey_cert:validate_extensions/7 function in lib/public_key/src/pubkey_cert.erl. The issue affects OTP from OTP 17.0 before OTP 26.2.5.21, OTP 27.3.4.12, OTP 28.5.0.1, and OTP 29.0.1, corresponding to public_key from 0.22 before 1.15.1.7, 1.17.1.3, 1.20.3.1, and 1.21.1.
Defensive priority
Defenders should prioritize verifying affected versions and applying patches due to potential certificate chain forgery risks.
Recommended defensive actions
- Verify affected OTP versions and apply patches
- Review and update trust store configurations
- Monitor for suspicious certificate activity
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems
- Review and update incident response plans
- Conduct a thorough risk assessment of affected systems
Evidence notes
The CVE record and NVD entry provide details on the vulnerability and affected versions. Patches are available from Erlang. The vulnerability allows certificate chain forgery in Erlang OTP's public_key, affecting TLS/mTLS endpoints. Defenders should verify exposure, apply patches, and review trust store configurations to prevent impersonation and identity verification bypass. The issue affects OTP from OTP 17.0 before OTP 26.2.5.21, OTP 27.3.4.12, OTP 28.5.0.1, and OTP 29.0.1, corresponding to public_key from 0.22 before 1.15.1.7, 1.7
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42789 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42789
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42789 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42789
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-42789.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-42789
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.erlang.org/doc/system/versions.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Product
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:39809
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:54757
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.