Known vulnerabilities in otp 22.0.4

Vendor: erlang
Software: otp
Version: 22.0.4
Software CPE: cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting otp version 22.0.4 otp 22.0.4 is affected by 15 vulnerabilities: 3 high, 7 medium, 5 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126652 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-32147
CWE-22 Low
No
No
26.2.5.20, 27.3.4.11, 28.4.3 21.04.2026 SB2026042143
SB2026051961
SB2026070964
and 2 more
#VU125777 - Incorrect Authorization
CVE-2026-28808
CWE-863 High
No
No
26.2.5.19, 27.3.4.10, 28.4.2 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 5 more
#VU125776 - Generation of Predictable Numbers or Identifiers
CVE-2026-28810
CWE-340 Low
No
No
26.2.5.19, 27.3.4.10, 28.4.2 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 1 more
#VU125775 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-23941
CWE-444 High
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125774 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23942
CWE-22 Low
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125773 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-23943
CWE-409 Medium
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 5 more
#VU125772 - Relative Path Traversal
CVE-2026-21620
CWE-23 Low
No
No
26.2.5.17, 27.3.4.8, 28.3.2 10.04.2026 SB2026041021
SB2026041023
SB2026041024
and 6 more
#VU125771 - Untrusted Search Path
CVE-2021-29221
CWE-426 Medium
No
No
23.2.3 10.04.2026 SB2026041020
#VU125768 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2016-1000107
CWE-601 Medium
No
No
26.2.5.15, 27.3.4.3, 28.1 10.04.2026 SB2025102052
#VU117393 - Resource exhaustion
CVE-2025-48041
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB2025102745
and 3 more
#VU117392 - Uncontrolled Recursion
CVE-2025-48040
CWE-674 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB20260105126
and 5 more
#VU117391 - Resource exhaustion
CVE-2025-48039
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB20260105126
and 7 more
#VU117390 - Resource exhaustion
CVE-2025-48038
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102054
SB2025102055
and 6 more
#VU111243 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4748
CWE-22 High
No
No
26.2.5.13, 27.3.4.1, 28.0.1 17.06.2025 SB2025061756
SB2025061922
SB20250711173
and 3 more
#VU108847 - Expected Behavior Violation
CVE-2025-46712
CWE-440 Low
No
No
25.3.2.21, 26.2.5.12, 27.3.4 09.05.2025 SB2025050954
SB2025052336
SB2025052337
and 2 more