Search CVE reports


Toggle filters

11 – 20 of 28 results


CVE-2025-4748

Medium priority

Some fixes available 4 of 9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-46712

Low priority

Some fixes available 4 of 9

Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-32433

High priority
Fixed

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-30211

Medium priority

Some fixes available 6 of 9

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2025-26618

Medium priority

Some fixes available 4 of 7

Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-53846

Medium priority
Fixed

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the...

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Not affected Not affected Not affected
Show less packages

CVE-2023-50966

Medium priority
Needs evaluation

erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

1 affected package

erlang-jose

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang-jose Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-37026

Medium priority

Some fixes available 9 of 12

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2020-35733

Medium priority
Not affected

An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Not affected Not affected
Show less packages

CVE-2020-25623

Medium priority
Not affected

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

1 affected package

erlang

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
erlang Not affected Not affected
Show less packages