What is CVE-2026-58227?
CVE-2026-58227 is a vulnerability in the Erlang/OTP ssl application where cycles are not detected when reconstructing an incomplete peer certificate chain during a TLS/DTLS handshake. The issue occurs in `ssl_certificate:handle_incomplete_chain/5`, which traverses issuer relationships, potentially leading to infinite loops or resource exhaustion. Affected systems should apply the Erlang/OTP update.
Azərbaycanca: CVE-2026-58227, Erlang/OTP ssl tətbiqində TLS/DTLS handshake zamanı natamam peer certificate chain bərpa edilərkən dövrlərin (cycles) aşkarlanmaması zəifliyidir. Bu, `ssl_certificate:handle_incomplete_chain/5` funksiyasında chain-in issuer əlaqələri əsasında gəzilməsi zamanı infinite loop və ya resurs tükənməsinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə Erlang/OTP yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What software is affected by CVE-2026-58227?
This vulnerability affects the ssl application in Erlang/OTP.
How can I protect against CVE-2026-58227?
Affected systems should apply the Erlang/OTP update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.