Known vulnerabilities in erlang
Vendor:
Fedoraproject
Software:
erlang
Software CPE:
cpe:2.3:o:fedoraproject:erlang:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
16
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
26.2.5.21-7.fc44
26.2.5.21-6.fc44
26.2.5.21-6.fc43
26.2.5.21-5.fc43
26.2.5.21-5.fc44
26.2.5.21-4.fc43
26.2.5.21-4.fc44
26.2.5.21-3.fc44
26.2.5.21-3.fc43
26.2.5.19-1.fc44
26.2.5.19-1.fc43
26.2.5.19-1.fc42
26.2.5.17-1.fc43
26.2.5.17-1.fc42
19.3.6.4-1.fc26
19.3.6.4-1.fc27
18.3.4.5-2.fc24
19.3-2.fc26
19.3-2.fc25
17.4-5.fc23
R16B-03.11.el7
17.4-4.fc21
17.4-4.fc22
17.4-1.fc21
17.3.4-3.fc21
R16B-03.10.el7
R16B-03.9.el7
R14B-03.3.el6
R14B-02.1.el6
23.2.3-1.fc33
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146824 - Selection of Less-Secure Algorithm During Negotiat CVE-2026-55953 |
CWE-757 | High | 26.2.5.21-5.fc43, 26.2.5.21-5.fc44, 26.2.5.21-6.fc43, 26.2.5.21-6.fc44, 26.2.5.21-7.fc44 | 02.09.2026 |
SB20260902104 SB20260902105 SB20260902106 and 9 more |
||
| #VU146822 - Uncontrolled Recursion CVE-2026-58227 |
CWE-674 | Medium | 26.2.5.21-7.fc44 | 02.09.2026 |
SB20260902104 SB20260902107 SB20260902108 and 5 more |
||
| #VU146821 - Allocation of Resources Without Limits or Throttling CVE-2026-59251 |
CWE-770 | Medium | 26.2.5.21-7.fc44 | 02.09.2026 |
SB20260902104 SB20260902108 SB20260902112 and 1 more |
||
| #VU136826 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-54886 |
CWE-835 | Low | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070297 SB2026071054 SB2026071055 and 7 more |
||
| #VU136825 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel CVE-2026-54891 |
CWE-924 | Medium | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070297 SB2026071054 SB2026071055 and 7 more |
||
| #VU136823 - Improper Validation of Specified Quantity in Input CVE-2026-55952 |
CWE-1284 | Medium | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070297 SB2026071054 SB2026071055 and 7 more |
||
| #VU136821 - Exposure of sensitive information to an unauthorized actor CVE-2026-48855 |
CWE-200 | Low | 26.2.5.21-3.fc43, 26.2.5.21-3.fc44 | 02.07.2026 |
SB2026070296 SB2026070301 SB2026070302 and 7 more |
||
| #VU136819 - Comparison using wrong factors CVE-2026-48860 |
CWE-1025 | Low | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070296 SB2026071054 SB2026071055 and 2 more |
||
| #VU136818 - Server-Side Request Forgery (SSRF) CVE-2026-48858 |
CWE-918 | Low | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070296 SB2026071054 SB2026071055 and 7 more |
||
| #VU136817 - Stack-based buffer overflow CVE-2026-49759 |
CWE-121 | Medium | 26.2.5.21-4.fc43, 26.2.5.21-4.fc44 | 02.07.2026 |
SB2026070296 SB2026071054 SB2026071055 and 7 more |
||
| #VU125777 - Incorrect Authorization CVE-2026-28808 |
CWE-863 | High | 26.2.5.19-1.fc42, 26.2.5.19-1.fc43, 26.2.5.19-1.fc44 | 10.04.2026 |
SB2026041031 SB2026041046 SB2026041047 and 6 more |
||
| #VU125776 - Generation of Predictable Numbers or Identifiers CVE-2026-28810 |
CWE-340 | Low | 26.2.5.19-1.fc42, 26.2.5.19-1.fc43, 26.2.5.19-1.fc44 | 10.04.2026 |
SB2026041031 SB2026041046 SB2026041047 and 4 more |
||
| #VU125772 - Relative Path Traversal CVE-2026-21620 |
CWE-23 | Low | 26.2.5.17-1.fc42, 26.2.5.17-1.fc43 | 10.04.2026 |
SB2026041021 SB2026041023 SB2026041024 and 6 more |
||
| #VU125769 - Improper Authentication CVE-2020-35733 |
CWE-287 | Medium | 23.2.3-1.fc33 | 10.04.2026 |
SB2026041018 SB2021012150 SB20210120137 |
||
| #VU11845 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2017-1000385 |
CWE-300 | Low | 19.3.6.4-1.fc26, 19.3.6.4-1.fc27 | 16.04.2018 |
SB2017120816 SB2018041212 SB2018031524 and 6 more |
||
| #VU40408 - Exposure of sensitive information to an unauthorized actor CVE-2015-2774 |
CWE-200 | Medium | R16B-03.11.el7, 17.4-4.fc21, 17.4-4.fc22, 17.4-5.fc23 | 08.04.2016 |
SB2015080604 SB2015080605 SB2015080705 and 2 more |