Known vulnerabilities in otp 25.0.1

Vendor: erlang
Software: otp
Version: 25.0.1
Software CPE: cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting otp version 25.0.1 otp 25.0.1 is affected by 17 vulnerabilities: 1 critical, 4 high, 7 medium, 5 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126652 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-32147
CWE-22 Low
No
No
26.2.5.20, 27.3.4.11, 28.4.3 21.04.2026 SB2026042143
SB2026051961
SB2026070964
and 2 more
#VU125777 - Incorrect Authorization
CVE-2026-28808
CWE-863 High
No
No
26.2.5.19, 27.3.4.10, 28.4.2 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 5 more
#VU125776 - Generation of Predictable Numbers or Identifiers
CVE-2026-28810
CWE-340 Low
No
No
26.2.5.19, 27.3.4.10, 28.4.2 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 1 more
#VU125775 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-23941
CWE-444 High
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125774 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23942
CWE-22 Low
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125773 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-23943
CWE-409 Medium
No
No
26.2.5.18, 27.3.4.9, 28.4.1 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 5 more
#VU125772 - Relative Path Traversal
CVE-2026-21620
CWE-23 Low
No
No
26.2.5.17, 27.3.4.8, 28.3.2 10.04.2026 SB2026041021
SB2026041023
SB2026041024
and 6 more
#VU125768 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2016-1000107
CWE-601 Medium
No
No
26.2.5.15, 27.3.4.3, 28.1 10.04.2026 SB2025102052
#VU117393 - Resource exhaustion
CVE-2025-48041
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB2025102745
and 3 more
#VU117392 - Uncontrolled Recursion
CVE-2025-48040
CWE-674 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB20260105126
and 5 more
#VU117391 - Resource exhaustion
CVE-2025-48039
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102180
SB20260105126
and 7 more
#VU117390 - Resource exhaustion
CVE-2025-48038
CWE-400 Medium
No
No
26.2.5.15, 27.3.4.3, 28.0.3 20.10.2025 SB2025102052
SB2025102054
SB2025102055
and 6 more
#VU111243 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4748
CWE-22 High
No
No
26.2.5.13, 27.3.4.1, 28.0.1 17.06.2025 SB2025061756
SB2025061922
SB20250711173
and 3 more
#VU108847 - Expected Behavior Violation
CVE-2025-46712
CWE-440 Low
No
No
25.3.2.21, 26.2.5.12, 27.3.4 09.05.2025 SB2025050954
SB2025052336
SB2025052337
and 2 more
#VU107594 - Missing Authentication for Critical Function
CVE-2025-32433
CWE-306 Critical
Public exploit available
Exploited
25.3.2.20, 26.2.5.11, 27.3.3 17.04.2025 SB2025041757
SB2025041763
SB2025042002
and 9 more
#VU106951 - Uncontrolled Memory Allocation
CVE-2025-26618
CWE-789 Medium
No
No
25.3.2.18, 26.2.5.9, 27.2.4 03.04.2025 SB2025040369
SB2025040384
SB2025040385
and 6 more
#VU69581 - Improper Authentication
CVE-2022-37026
CWE-287 High
No
No
23.3.4.15, 24.3.4.2, 25.0.2 24.11.2022 SB2022112429
SB2022112431
SB2022112534
and 10 more