Known vulnerabilities in erlang

Software: erlang
Software CPE: cpe:2.3:o:fedoraproject:erlang:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 16
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting erlang erlang is affected by 16 known vulnerabilities: 2 high, 7 medium, 7 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146824 - Selection of Less-Secure Algorithm During Negotiat
CVE-2026-55953
CWE-757 High
No
No
26.2.5.21-5.fc43, 26.2.5.21-5.fc44, 26.2.5.21-6.fc43, 26.2.5.21-6.fc44, 26.2.5.21-7.fc44 02.09.2026 SB20260902104
SB20260902105
SB20260902106
and 9 more
#VU146822 - Uncontrolled Recursion
CVE-2026-58227
CWE-674 Medium
No
No
26.2.5.21-7.fc44 02.09.2026 SB20260902104
SB20260902107
SB20260902108
and 5 more
#VU146821 - Allocation of Resources Without Limits or Throttling
CVE-2026-59251
CWE-770 Medium
No
No
26.2.5.21-7.fc44 02.09.2026 SB20260902104
SB20260902108
SB20260902112
and 1 more
#VU136826 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-54886
CWE-835 Low
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 7 more
#VU136825 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVE-2026-54891
CWE-924 Medium
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 7 more
#VU136823 - Improper Validation of Specified Quantity in Input
CVE-2026-55952
CWE-1284 Medium
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 7 more
#VU136821 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48855
CWE-200 Low
No
No
26.2.5.21-3.fc43, 26.2.5.21-3.fc44 02.07.2026 SB2026070296
SB2026070301
SB2026070302
and 7 more
#VU136819 - Comparison using wrong factors
CVE-2026-48860
CWE-1025 Low
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070296
SB2026071054
SB2026071055
and 2 more
#VU136818 - Server-Side Request Forgery (SSRF)
CVE-2026-48858
CWE-918 Low
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070296
SB2026071054
SB2026071055
and 7 more
#VU136817 - Stack-based buffer overflow
CVE-2026-49759
CWE-121 Medium
No
No
26.2.5.21-4.fc43, 26.2.5.21-4.fc44 02.07.2026 SB2026070296
SB2026071054
SB2026071055
and 7 more
#VU125777 - Incorrect Authorization
CVE-2026-28808
CWE-863 High
No
No
26.2.5.19-1.fc42, 26.2.5.19-1.fc43, 26.2.5.19-1.fc44 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 6 more
#VU125776 - Generation of Predictable Numbers or Identifiers
CVE-2026-28810
CWE-340 Low
No
No
26.2.5.19-1.fc42, 26.2.5.19-1.fc43, 26.2.5.19-1.fc44 10.04.2026 SB2026041031
SB2026041046
SB2026041047
and 4 more
#VU125772 - Relative Path Traversal
CVE-2026-21620
CWE-23 Low
No
No
26.2.5.17-1.fc42, 26.2.5.17-1.fc43 10.04.2026 SB2026041021
SB2026041023
SB2026041024
and 6 more
#VU125769 - Improper Authentication
CVE-2020-35733
CWE-287 Medium
No
No
23.2.3-1.fc33 10.04.2026 SB2026041018
SB2021012150
SB20210120137
#VU11845 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2017-1000385
CWE-300 Low
Available
Exploited
19.3.6.4-1.fc26, 19.3.6.4-1.fc27 16.04.2018 SB2017120816
SB2018041212
SB2018031524
and 6 more
#VU40408 - Exposure of sensitive information to an unauthorized actor
CVE-2015-2774
CWE-200 Medium
No
No
R16B-03.11.el7, 17.4-4.fc21, 17.4-4.fc22, 17.4-5.fc23 08.04.2016 SB2015080604
SB2015080605
SB2015080705
and 2 more