CVE-2026-23943 is a Denial of Service vulnerability in Erlang OTP SSH, affecting versions from 17.0 up to 28.4.1, caused by improper handling of highly compressed data (compression bomb). An unauthenticated attacker can exploit this by sending specially crafted zlib compressed SSH packets, which are inflated without size limits, leading to memory exhaustion and system crashes. This network-based attack has low complexity and a CVSS score of 6.9 (Medium), with each packet potentially decompressing 255 MB from 256 KB of wire data. Currently, there is no evidence of active exploitation, nor are public exploit codes or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0, < 26.2.5.18CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 27.0, < 27.3.4.9CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 28.0, < 28.4.1CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 3.0.1, < 5.1.4.14CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.11.6CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.