Erlang's vulnerability profile reflects a small but prominently embedded platform for distributed and fault-tolerant systems, where disclosures concentrate in core runtime and cryptographic components such as OTP, SSL, and the Inets HTTP library. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the security-sensitive role of these foundational libraries in production telecom, messaging, and real-time systems. The exposure recurs through weakness classes including improper certificate validation, path traversal, sensitive information disclosure, and authorization flaws that reflect both the complexity of TLS state management and the input-handling demands of protocol-facing components. Defenders should treat Erlang/OTP security updates as high-priority for deployed systems, particularly those accepting remote connections or handling cryptographic validation; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Erlang over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32433CRITICAL Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform | Apr 16, 2025 | 10.0 | 98 | YES | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2017-1000385MEDIUM The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages wit | Dec 12, 2017 | 5.9 | 42 | NO | YES |
CVE-2026-55952HIGH The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passi | Jul 2, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-49759HIGH Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.
The s | Jun 10, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-28808CRITICAL Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.
When sc | Apr 7, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-55950MEDIUM Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sess | Jul 2, 2026 | 5.9 | 31 | NO | NO |
CVE-2026-42790HIGH Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in T | May 27, 2026 | 8.1 | 31 | NO | NO |
CVE-2022-37026CRITICAL In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and D | Sep 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-13802CRITICAL Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification. | Sep 2, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Erlang.
Media articles that mention a CVE ID that affects a product developed by Erlang — matched by CVE ID, not by vendor name.