Search CVE reports


Toggle filters

1 – 10 of 17 results


CVE-2025-4748

Medium priority

Some fixes available 3 of 8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-46712

Low priority

Some fixes available 3 of 8

Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-32433

High priority
Fixed

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-30211

Medium priority

Some fixes available 5 of 8

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2025-26618

Medium priority

Some fixes available 4 of 7

Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-50966

Medium priority
Needs evaluation

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

1 affected package

erlang-jose

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang-jose Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-37026

Medium priority

Some fixes available 8 of 11

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2020-35733

Medium priority
Not affected

An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Not affected Not affected
Show less packages

CVE-2020-25623

Medium priority
Not affected

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Not affected Not affected
Show less packages

CVE-2017-1000385

Medium priority

Some fixes available 3 of 4

The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages with the server's private key (this is a variation of...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang
Show less packages