Server-Side Request Forgery Vulnerability in Erlang/OTP's FTP Module
CVE-2026-48858
What is CVE-2026-48858?
A Server-Side Request Forgery (SSRF) vulnerability exists in Erlang/OTP's FTP module, specifically within the ftp_internal module. This flaw permits malicious actors to exploit unvalidated PASV response IP addresses to redirect data connections to arbitrary internal hosts or ports. Through this vulnerability, an attacker can execute FTP bounce attacks, allowing them to read from or write to unauthorized locations. The vulnerability arises due to insufficient validation in the PASV handler of the ftp_internal module, enabling attackers to compromise FTP operations against third-party hosts and internal systems. The affected versions include inets 5.10.4 to 6.5, and OTP from 17.4 to 20.3, highlighting the urgency of applying the recommended security patches.
Affected Version(s)
OTP 5.10.4 < 7.0
OTP 1.0
OTP 17.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
