Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23943

21
FAUCET Score

CVE-2026-23943 is a Denial of Service vulnerability in Erlang OTP SSH, affecting versions from 17.0 up to 28.4.1, caused by improper handling of highly compressed data (compression bomb). An unauthenticated attacker can exploit this by sending specially crafted zlib compressed SSH packets, which are inflated without size limits, leading to memory exhaustion and system crashes. This network-based attack has low complexity and a CVSS score of 6.9 (Medium), with each packet potentially decompressing 255 MB from 256 KB of wire data. Currently, there is no evidence of active exploitation, nor are public exploit codes or significant community discussion available.

Impacted Technologies

VendorProductVersion(s)CPE
>= 17.0, < 26.2.5.18CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
>= 27.0, < 27.3.4.9CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
>= 28.0, < 28.4.1CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
>= 3.0.1, < 5.1.4.14CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:*
>= 5.2, < 5.2.11.6CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.64%
Probability of exploitation in next 30 days
EPSS Percentile
47.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0064 is in the 30th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 20976-17084Fixed in: 26.2.5.18-1
microsoftpatch availablevia msrc
Product: 20541-17086Fixed in: 25.3.2.21-5
microsoftpatch availablevia msrc
Product: azl3 erlang 26.2.5.17-1 on Azure Linux 3.0Fixed in: 26.2.5.18-1
microsoftpatch availablevia msrc
Product: cbl2 erlang 25.3.2.21-4 on CBL Mariner 2.0Fixed in: 25.3.2.21-5

Vendor Advisories (1)

microsoft2026-Mar/CVE-2026-23943Moderate

Pre-auth SSH DoS via unbounded zlib inflate

Mar 10, 2026

References

cna.erlef.org / cves/CVE-2026-23943.html
Vendor Advisory
github.com / erlang/otp/commit/0c1c04b191f6ab940e8fcfabce39eb5a8a6440a4
Patch
github.com / erlang/otp/commit/43a87b949bdff12d629a8c34146711d9da93b1b1
Patch
github.com / erlang/otp/commit/93073c3bd338c60cd2bae715ce6a1d4ffc1a8fd3
Patch
github.com / erlang/otp/security/advisories/GHSA-c836-qprm-jw9r
Vendor Advisory
osv.dev / vulnerability/EEF-CVE-2026-23943
Third Party Advisory
erlang.org / doc/system/versions.html
Product