Where
-Infinity
0

Erlang Erlang\/otpPlaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl

Risk 27
Severity
6.3
First published (updated )

Erlang Erlang\/otpDTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions

Risk 47
Severity
8.7
First published (updated )

Erlang Erlang\/otpSSH SFTP server denial of service via extended channel data infinite loop

Risk 26
Severity
5.3
First published (updated )

Erlang Erlang\/otpTLS 1.3 server denial of service via malformed ClientHello pre-shared key extension

Risk 43
Severity
8.2
First published (updated )

Erlang Erlang\/otpDTLS server cookie bypass during startup window due to empty initial cookie secret

Risk 29
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Erlang Erlang\/otpSFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root

Risk 22
Severity
2.3
First published (updated )

Erlang OTPBuffer Overflow

Risk 33
Severity
7
First published (updated )

Erlang Erlang\/inetshttpc leaks Authorization header to cross-origin redirect targets

Risk 40
Severity
7.1
First published (updated )

Erlang Erlang\/otpSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured

Risk 38
Severity
2.3
First published (updated )

Erlang Erlang\/otpDistribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist

Risk 66
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Erlang Erlang\/otpftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks

Risk 40
Severity
6.3
First published (updated )

Erlang Erlang/OTPSSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration

Risk 29
Severity
6.3
First published (updated )

Erlang ertsStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash

Risk 57
Severity
8.8
First published (updated )

Erlang Erl InterfaceStack Buffer Overflow in ei_s_print_term at Very Large Integer

Risk 38
Severity
6.9
First published (updated )

Erlang OTPImproper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key m…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Erlang Erlang\/otpnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification

Risk 59
Severity
7.6
First published (updated )

Erlang Erlang\/otpOCSP responder certificate validity period not checked in public_key

Risk 37
Severity
6.3
First published (updated )

Erlang Erlang\/otpNon-CA certificate accepted as intermediate issuer in public_key path validation

Risk 58
Severity
7
First published (updated )

Erlang Erlang 29End of life details

EOL
May 11, 2029
First published (updated )

Erlang Erlang\/otpSFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT

Risk 26
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Erlang OTP (inets)Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to…

Risk 33
Severity
7
First published (updated )

Erlang Erlang\/inetsScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)

Risk 86
Severity
8.3
First published (updated )

Erlang Erlang\/otpOCSP designated-responder authorization bypass via missing signature verification

Risk 55
Severity
7.6
First published (updated )

Erlang Erlang\/otpPredictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver

Risk 29
Severity
6.3
First published (updated )

hex/esamlXXE in esaml SAML library allows local file read and potential SSRF

Risk 29
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Erlang Erlang\/inetsRequest smuggling via first-wins Content-Length parsing in inets httpd

Risk 76
Severity
7
First published (updated )

Erlang Erlang\/otpPre-auth SSH DoS via unbounded zlib inflate

Risk 33
Severity
6.9
First published (updated )

Erlang Erlang\/otpSFTP root escape via component-agnostic prefix check in ssh_sftpd

Risk 34
Severity
5.3
First published (updated )

hexpm/hex_coreUnsafe Deserialization of Erlang Terms in hex_core

Risk 46
Severity
2
First published (updated )

Erlang OTPSSH_FXP_OPENDIR may Lead to Exhaustion of File Handles

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203