Erlang/OTP 28.4.1 patch release fixes several security vulnerabilities across multiple applications. Key fixes include: an HTTP request smuggling vulnerability in inets httpd (CVE-2026-23941) via multiple Content-Length headers; an SFTP path traversal vulnerability in ssh allowing access to sibling directories (CVE-2026-23942); a decompression bomb vulnerability in SSH zlib compression that could cause memory exhaustion (CVE-2026-23943); a DNS TSIG validation bypass in kernel; and a memory leak in crypto's engine_load. The ssl application also receives a TLS-1.3 certificate request fix and documentation improvements for socket options.

4m read timeFrom erlangforums.com
Post cover image
Table of contents
crypto-5.8.3inets-9.6.1kernel-10.6.1ssh-5.5.1ssl-11.5.3Thanks to

Sort: