OVERVIEW CVE-2026-28810 is a DNS cache poisoning vulnerability in the Erlang/OTP kernel, specifically affecting the inet_res DNS resolver module. The flaw stems from the use of predictable, sequential 16-bit transaction IDs for UDP queries combined with the absence of source port randomization. This allows attackers to forge DNS responses and poison DNS caches, as response validation relies almost exclusively on the transaction ID. The vulnerability impacts OTP versions 17.0 through 28.4.2 and their corresponding kernel components, affecting systems where inet_res is deployed in untrusted network environments. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.7 (LOW) with an attack vector of network-based but requiring high complexity (AC:H), no privileges (PR:N), and no user interaction (UI:N). The impact is limited to integrity compromise with no confidentiality or availability effects. However, the moderate FAUCET Risk Score of 36.0/100 suggests elevated concern beyond the CVSS rating. The root cause violates RFC 5452 recommendations for DNS security and represents a fundamental design flaw in the resolver implementation. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat tracking lists. The EPSS score of 0.000660 indicates minimal probability of exploitation in the wild. No public exploit code or active exploitation campaigns have been reported. However, the vulnerability remains practically exploitable for threat actors with network visibility to observe or predict transaction IDs, particularly in untrusted network scenarios despite the resolver's design intent for trusted environments only.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0, < 26.2.5.19CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 27.0, < 27.3.4.10CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 28.0, < 28.4.2CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.