What is CVE-2026-55953?
The Erlang/OTP TLS 1.2 (and earlier) and DTLS client fails to verify that the cipher suite selected by the server was among those offered by the client. This vulnerability could allow a server to choose a weak cipher suite not supported by the client. Updating Erlang/OTP to the latest version is recommended.
Azərbaycanca: Erlang/OTP-də TLS 1.2 (və daha köhnə) və DTLS müştərisi server tərəfindən seçilmiş cipher suite-in müştəri tərəfindən təklif edilənlər arasında olub-olmadığını yoxlamır. Bu zəiflik, serverin müştərinin dəstəkləmədiyi zəif bir cipher suite seçməsinə imkan verə bilər. Təhlükəsizlik üçün Erlang/OTP-nin ən son versiyaya yenilənməsi tövsiyə olunur.
FAQ2
What can the CVE-2026-55953 vulnerability in Erlang/OTP lead to?
This vulnerability could allow a server to choose a weak cipher suite not supported by the client.
What is recommended to protect against CVE-2026-55953?
Updating Erlang/OTP to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.