What is CVE-2026-59251?
A vulnerability in Erlang/OTP's public_key module allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake, due to allocation of resources without limits during RFC 5280 policy processing. Applying available patches or updates to the affected Erlang/OTP versions is recommended to mitigate this issue.
Azərbaycanca: Erlang/OTP-nin public_key modulunda resurs limitasiyası olmaması səbəbindən TLS handshake zamanı xüsusi hazırlanmış X.509 sertifikat zənciri göndərilərək uzaqdan xidmət dayandırma (DoS) mümkündür. Bu zəiflik RFC 5280 siyasət emalı zamanı baş verir. Təsirə məruz qalan sistemlərdə paket yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
How is CVE-2026-59251 exploited in Erlang/OTP?
A remote unauthenticated attacker can exploit this vulnerability by sending a crafted X.509 certificate chain during the TLS handshake, causing allocation of resources without limits during RFC 5280 policy processing in the public_key module.
What is the recommended mitigation for CVE-2026-59251?
Applying available patches or updates to the affected Erlang/OTP versions is recommended to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.