Improper Certificate Validation in Erlang OTP - CVE-2026-32144
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass certificate-based authentication.
The vulnerability exists due to improper certificate validation in OCSP designated-responder authorization handling when validating OCSP responses. A remote attacker can provide a crafted OCSP response to bypass certificate-based authentication.
Exploitation requires control of, or a man-in-the-middle position over, the server being validated.
Affected software
Debian Linux
erlang (Debian package)
How to mitigate CVE-2026-32144
erlang (Debian package) - update to 1:27.3.4.1+dfsg-1+deb13u3