Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OTP — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in OTP, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Open Telecom Platform, a software framework used for building telecommunications systems, categorized under generic software weakness types. It collects security issues identified in OTP components across a broad historical range, capturing data from early releases through recent updates to ensure comprehensive coverage of legacy and modern codebases. Readers can utilize this resource to track vendor advisories from Ericsson and community contributors, gain a deeper understanding of specific weakness classes such as buffer overflows or improper input validation, and investigate a product’s vulnerability history to assess risk exposure over time. By centralizing this information, the page serves as a reference point for security analysts, developers, and system administrators who need to evaluate the security posture of OTP-based deployments. The data is organized to facilitate quick lookup and comparison, allowing users to identify patterns in vulnerability discovery and remediation efforts. This approach supports informed decision-making regarding patching strategies and system hardening measures without requiring manual searches across multiple disparate sources. The content reflects publicly available reports and advisory notices, providing a factual baseline for security assessments and compliance reviews. Users are encouraged to cross-reference this information with official vendor documentation and real-time threat intelligence feeds for the most current guidance.

Vendor: erlang

CVE IDTitleCVSSSeverityPublished
CVE-2026-54890 BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding CWE-191 8.2 High2026-07-27
CVE-2026-59251 Denial of service via exponential certificate policy tree growth in path validation CWE-770 8.7 High2026-07-27
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name CWE-120 8.3 High2026-07-27
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication CWE-757 9.1 Critical2026-07-27
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder CWE-195 5.1 Medium2026-07-27
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass CWE-23 4.8 Medium2026-07-27
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts CWE-755 6.3 Medium2026-07-27
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain CWE-674 8.7 High2026-07-27
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl CWE-924 6.3 Medium2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions CWE-367 8.7 High2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop CWE-835 5.3 Medium2026-07-02
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension CWE-1284 8.2 High2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret CWE-1394 6.3 Medium2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root CWE-204 2.3 Low2026-07-02
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets CWE-601 7.1 High2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist CWE-1025 7.5 High2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured CWE-200 2.3 Low2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks CWE-918 6.3 Medium2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration CWE-208 6.3 Medium2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash CWE-121 8.8 High2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer CWE-121 6.9 Medium2026-06-10
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification CWE-295 7.6 High2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key CWE-295 6.3 Medium2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation CWE-295 7.0 High2026-05-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT CWE-22 5.3 Medium2026-04-21
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) CWE-863 8.3 High2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification CWE-295 7.6 High2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver CWE-340 6.3 Medium2026-04-07
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd CWE-444 7.0 High2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate CWE-409 6.9 Medium2026-03-13

All 42 known CVE vulnerabilities affecting OTP with full Chinese analysis, references, and POCs where available.