Improper Validation of Specified Quantity in Input in Erlang OTP - CVE-2026-59696

 

Improper Validation of Specified Quantity in Input in Erlang OTP - CVE-2026-59696

Published: September 2, 2026


Vulnerability identifier: #VU146843
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59696
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper validation of specified quantity in input in stdlib integer conversion functions and uri_string:parse/1 when processing untrusted URL input or converting unbounded textual decimal representations and arbitrary-precision integers. A remote attacker can send a specially crafted input to cause a denial of service.

The render path performs integer string conversion inside a non-yielding C BIF, which can occupy a dirty scheduler thread for the full conversion, while the parse path is preemptible but can still consume significant processing time with extremely large inputs.


Affected software

Erlang OTP

How to mitigate CVE-2026-59696

Install security update from vendor's website.

Erlang OTP - addressed in versions 17.0, 27.3.4.17, 28.5.0.6, 29.0.6

External References

Related Security Bulletins