Erlang/OTP vulnerabilities
4 CVEs tracked
Erlang/OTP vendor is currently highlighted in our reports due to several critical memory corruption vulnerabilities affecting the BEAM virtual machine, specifically involving the 'binary_to_term/1' function (CVE-2026-55737) and the ERTS module (CVE-2026-54890). Key events include an integer underflow allowing excessive memory allocation, an out-of-bounds write that can crash the VM via crafted ETF payloads, a classic buffer overflow in the Megaco C driver with potential for remote code execution, and a TLS client flaw where the cipher suite selected by the server is not properly validated (CVE-2026-55953). Defenders should prioritize sanitizing 'binary_to_term/1' inputs from untrusted sources, applying network-level restrictions for systems using the Megaco driver, and ensuring strict TLS client cipher suite enforcement.
Azərbaycanca: Erlang/OTP vendoru cari hesabatlarımızda BEAM virtual maşını, xüsusilə 'binary_to_term/1' funksiyası (CVE-2026-55737) və ERTS modulu (CVE-2026-54890) daxil olmaqla, bir neçə kritik yaddaş korrupsiyası zəifliyi ilə əlaqədar diqqət mərkəzindədir. Əsas hadisələrə hücumçunun xüsusi hazırlanmış ETF yükü ilə virtual maşını çökdürməsinə imkan verən boşluqlar, TLS kliyentində şifrələmə dəstinin düzgün doğrulanmaması (CVE-2026-55953) və Megaco sürücüsündə uzaqdan kod icrası riski daşıyan klassik bufer daşması daxildir. Müdafiəçilər xüsusilə etibarsız mənbələrdən gələn `binary_to_term/1` girişlərini yoxlamalı, Megaco sürücüsünü istifadə edən sistemlərdə şəbəkə səviyyəsində məhdudiyyətlər tətbiq etməli və TLS kliyent konfiqurasiyalarının təhlükəsiz şifrələmə dəstlərini tətbiq etdiyinə əmin olmalıdırlar.
This vendor's CVEs4
This hub is built from skopnix's own reporting on Erlang/OTP: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.