Known vulnerabilities in Erlang OTP

Vendor: erlang
Software: Erlang OTP
Software CPE: cpe:2.3:a:erlang:otp:*:*:*:*:*:*:*:*
Total vulnerabilities: 67
Public exploits: 3
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Erlang OTP Erlang OTP is affected by 67 known vulnerabilities: 1 critical, 11 high, 39 medium, 16 low Critical High Medium Low

Vulnerabilities (67)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146843 - Improper Validation of Specified Quantity in Input
CVE-2026-59696
CWE-1284 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146842 - Allocation of Resources Without Limits or Throttling
CVE-2026-55951
CWE-770 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146841 - Incorrect Authorization
CVE-2026-74994
CWE-863 Low
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146840 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-73812
CWE-444 High
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146839 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-66357
CWE-444 High
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146838 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-73276
CWE-444 High
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146837 - Missing Release of Resource after Effective Lifetime
CVE-2026-71380
CWE-772 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146836 - Improper Handling of Case Sensitivity
CVE-2026-73270
CWE-178 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146835 - Path Equivalence: \'//multiple/leading/slash\'
CVE-2026-66835
CWE-50 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146834 - Heap-based Buffer Overflow
CVE-2026-75538
CWE-122 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146833 - Improper Validation of Specified Quantity in Input
CVE-2026-71562
CWE-1284 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146832 - Improper Validation of Specified Quantity in Input
CVE-2026-70409
CWE-1284 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146831 - Improper Validation of Specified Quantity in Input
CVE-2026-70405
CWE-1284 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146830 - Missing Release of Resource after Effective Lifetime
CVE-2026-69664
CWE-772 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146829 - Allocation of Resources Without Limits or Throttling
CVE-2026-74835
CWE-770 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146828 - Allocation of Resources Without Limits or Throttling
CVE-2026-70399
CWE-770 Medium
No
No
27.3.4.17, 28.5.0.6, 29.0.6 02.09.2026 SB20260902111
#VU146827 - Improper Handling of Exceptional Conditions
CVE-2026-42792
CWE-755 Medium
No
No
27.3.4.15, 28.5.0.4, 29.0.4 02.09.2026 SB20260902104
SB20260902107
SB20260902108
and 4 more
#VU146826 - Relative Path Traversal
CVE-2026-47078
CWE-23 Medium
No
No
27.3.4.15, 28.5.0.4, 29.0.4 02.09.2026 SB20260902104
SB20260902108
SB20260902112
and 1 more
#VU146825 - Signed to Unsigned Conversion Error
CVE-2026-55737
CWE-195 Low
No
No
27.3.4.15, 28.5.0.4, 29.0.4 02.09.2026 SB20260902104
SB20260902107
SB20260902108
and 4 more
#VU146824 - Selection of Less-Secure Algorithm During Negotiat
CVE-2026-55953
CWE-757 High
No
No
27.3.4.15, 28.5.0.4, 29.0.4 02.09.2026 SB20260902104
SB20260902105
SB20260902106
and 6 more


Showing elements 1 - 20 out of 67