Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Erlang

First CVE: Jan 15, 2009Active for: 18 yearsTotal CVEs: 39
65.9
VTI Score
TOP TARGET

Erlang's vulnerability profile reflects a small but prominently embedded platform for distributed and fault-tolerant systems, where disclosures concentrate in core runtime and cryptographic components such as OTP, SSL, and the Inets HTTP library. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the security-sensitive role of these foundational libraries in production telecom, messaging, and real-time systems. The exposure recurs through weakness classes including improper certificate validation, path traversal, sensitive information disclosure, and authorization flaws that reflect both the complexity of TLS state management and the input-handling demands of protocol-facing components. Defenders should treat Erlang/OTP security updates as high-priority for deployed systems, particularly those accepting remote connections or handling cryptographic validation; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
2.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Erlang over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 15, 2009
17 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-32433CRITICAL
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform
Apr 16, 202510.098YESYES
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2017-1000385MEDIUM
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. This allows an attacker to decrypt content or sign messages wit
Dec 12, 20175.942NOYES
CVE-2026-55952HIGH
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passi
Jul 2, 20267.535NONO
CVE-2026-49759HIGH
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The s
Jun 10, 20268.233NONO
CVE-2026-28808CRITICAL
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When sc
Apr 7, 20269.833NONO
CVE-2026-55950MEDIUM
Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sess
Jul 2, 20265.931NONO
CVE-2026-42790HIGH
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in T
May 27, 20268.131NONO
CVE-2022-37026CRITICAL
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and D
Sep 21, 20229.831NONO
CVE-2020-13802CRITICAL
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
Sep 2, 20209.831NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
46%
31%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.1%)
Network35 (89.7%)
Unknown2 (5.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (66.7%)
High11 (28.2%)
Unknown2 (5.1%)
User Interaction
None33 (84.6%)
Unknown2 (5.1%)
Required4 (10.3%)
Privileges Required
Low8 (20.5%)
High0 (0.0%)
None29 (74.4%)
Unknown2 (5.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 99th percentile
Metasploit
2 CVEs
5.1% of CVEs· 98th percentile
Nuclei
2 CVEs
5.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Erlang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Erlang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Erlang's Products

View all 5 CNAs →

Top CWEs