These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An attacker connecting to an open Erlang TCP port using the inet driver with {packet,4} mode can cause a signed overflow in packet length calculation, potentially overflowing the receive buffer into the VM allocator area. This issue affects OTP versions before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6. The vulnerability could lead to system crashes and potential stability issues. Defenders should assess [truncated]
CVE-2026-74994 affects OTP's inets httpd server when configured with dets or mnesia authentication backends and multiple directory configuration blocks. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue impacts OTP versions from 17.0 before 27.3.4.17, from 28.0 before 28.5.0.6, and from 29.0 before 29.0.6. The CVE recor [truncated]
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked requests, affecting Erlang OTP versions before OTP 27.3.4.17, OTP 28.5.0.6, and OTP 29.0.6. This issue, tracked as CVE-2026-74835, has a CVSS score of 8.7 and is considered high severity. The vulnerability allows attackers to bypass body-size limits on chunked requests, potentially leading to denial-of-service [truncated]
CVE-2026-73812 is a vulnerability in the Erlang OTP inets component that can lead to a front-end/back-end desync. The issue arises from the improper handling of duplicate Content-Length headers and the co-presence of TE and CL, which can be exploited for HTTP request smuggling. This issue affects OTP versions from 17.0 before 27.3.4.17, from 28.0 before 28.5.0.6, and from 29.0 before 29.0.6, corresponding [truncated]
CVE-2026-73276 is a high-severity vulnerability in Erlang's OTP that could allow for HTTP Request Smuggling attacks. The issue affects OTP versions from 22.2 before 27.3.4.17, from 28.0 before 28.5.0.6, and from 29.0 before 29.0.6. This vulnerability has a CVSS score of 8.3 and is considered HIGH severity. Defenders should prioritize patching or mitigating this vulnerability, especially in systems that us [truncated]
CVE-2026-73270 Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive. This vulnerability affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before [truncated]
CVE-2026-71562 is an Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc. A malicious or compromised HTTP server can degrade availability by returning a numeric header with a very long run of digits. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 befor [truncated]
A Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corre [truncated]
CVE-2026-70409 Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. The vulnerability affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to elda [truncated]
The CVE-2026-70405 vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6. Defenders should verify exposure, assess the need for updates or compensating contr [truncated]
CVE-2026-70399 is an Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd. An unauthenticated remote attacker can cause denial of service by opening and holding open a large number of connections. The vulnerability affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6.
The CVE-2026-69664 vulnerability is a Missing Release of Resource after Effective Lifetime issue in Erlang/OTP inets httpd. This high-severity vulnerability allows unauthenticated remote attackers to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. As a result, the worker serving the connection is never released, occupying every available [truncated]
A Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. This issue arises from the httpd_request:validate_uri/1 function not collapsing empty path segments, which enables the attack. Defenders and administrators of systems using Erlang/OTP inets httpd, particul [truncated]
CVE-2026-66357 is a vulnerability in the Erlang OTP inets component that affects HTTP request smuggling. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. The issue affects OTP from version 17.0 before 27.3.4.17, from 28.0 before 28.5.0.6, and from 29.0 before 29.0.6. This vulnerability is caused by the missing implementation of obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header con [truncated]
CVE-2026-59696 is an Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib. A remote attacker can degrade availability by supplying a URI with a very long port component. The issue affects OTP versions from 21.0 before 27.3.4.17, from 28.0 before 28.5.0.6, and from 29.0 before 29.0.6. This vulnerability can lead to increased processing time for URI parsing and potential den [truncated]
CVE-2026-59251 is a high-severity vulnerability in Erlang/OTP's public_key certificate path validation. A remote unauthenticated attacker can cause a denial of service by sending a crafted X.509 certificate chain during the TLS handshake. The vulnerability is due to the lack of limits in the certificate policy tree maintained by pubkey_policy_tree, which can grow exponentially with the number of policies [truncated]
CVE-2026-59250 is a high-severity buffer overflow vulnerability in the Erlang/OTP megaco flex scanner C driver. A remote unauthenticated attacker can exploit this vulnerability by sending a single text-encoded H.248/Megaco message containing an oversized property parm name, potentially leading to remote code execution or a denial-of-service crash. The vulnerability occurs in the flex scanner before any gr [truncated]
The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake, affecting OTP from OTP 23.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15. This issue allows an unauthenticated remote attacker to exhaust available memory and crash the BEAM node by sending a crafted certificate chain in a TLS or DTLS Certificate handshake message.
CVE-2026-55953 is a critical vulnerability in the Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client. The client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. This allows an on-path attacker to respond with a ServerHello selecting an anonymous key exchange suite, bypassing the verify_peer and cacerts configuration. [truncated]
CVE-2026-55737 is a Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts. An attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 can corrupt the BEAM heap pointer and crash the virtual machine. The issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15. This vulnerability has a medium severity and [truncated]
The CVE record for CVE-2026-54890 was published on 2026-07-27T16:17:41.437Z and has not been modified since then. The NVD entry is currently Received. This Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. The crash is a VM-level abort, not an Erlang-level exception. Any applica [truncated]
CVE-2026-47078 is a Relative Path Traversal vulnerability in the Erlang OTP stdlib zip module. The vulnerability allows writing files outside the intended extraction directory via a crafted zip archive. The issue affects OTP from OTP 27.1 before OTP 29.0.4, OTP 28.5.0.4, and OTP 27.3.4.15. This vulnerability is associated with program file lib/stdlib/src/zip.erl. The zip:unzip/1,2 and zip:extract/1,2 func [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T16:17:06.257Z and has not been modified since then. This Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept functi [truncated]
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. This vulnerability allows an unauthenticated remote attacker to send a single crafted ClientHello to a TLS 1.3 server with session tickets enabled and permanently disrupt session ticket han [truncated]
A high-severity Time-of-check Time-of-use (TOCTOU) race condition vulnerability was discovered in Erlang/OTP ssl, specifically in the dtls_packet_demux module. This vulnerability allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. The attack is pre-authentication and requires the attacker to send UDP datagrams containing valid ClientHello messages from the same sourc [truncated]
The CVE-2026-54887 vulnerability is associated with a Use of Default Cryptographic Key issue in Erlang/OTP ssl (DTLS server). This allows for predictable DTLS cookie computation during the startup window, enabling source address verification bypass. The vulnerability affects OTP versions from 20.0 before 29.0.3, 28.5.0.3, and 27.3.4.14, corresponding to ssl versions 8.2 before 11.7.3, 11.6.0.3, and 11.2.1 [truncated]
CVE-2026-54886 is an infinite loop vulnerability in the Erlang OTP SSH (ssh_sftpd module). An authenticated SFTP user can render an SFTP channel permanently unresponsive by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the SFTP packet size limit. The vulnerability affects OTP from OTP 17.0 until OTP 29.0.3, 28.5.0.3, and 27.3.4.14 corresponding to ssh [truncated]
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. This issue arises from the SSH_FXP_REALPATH handler in ssh_sftpd calling relate_file_name/3 with Canonicalize=false, unlike other SFTP operation handlers. Consequently, .. components in the requested [truncated]
A Stack-based Buffer Overflow vulnerability was discovered in Erlang OTP (erl_interface), specifically in the program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 ch [truncated]
CVE-2026-49759 is a Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv). An unauthenticated remote attacker can crash the BEAM VM by sending a crafted SCTP ERROR chunk. The vulnerability exists in the sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c, which parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] a [truncated]