Server-Side Request Forgery Vulnerability in Erlang/OTP's FTP Module
CVE-2026-48858

6.3MEDIUM

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-48858?

A Server-Side Request Forgery (SSRF) vulnerability exists in Erlang/OTP's FTP module, specifically within the ftp_internal module. This flaw permits malicious actors to exploit unvalidated PASV response IP addresses to redirect data connections to arbitrary internal hosts or ports. Through this vulnerability, an attacker can execute FTP bounce attacks, allowing them to read from or write to unauthorized locations. The vulnerability arises due to insufficient validation in the PASV handler of the ftp_internal module, enabling attackers to compromise FTP operations against third-party hosts and internal systems. The affected versions include inets 5.10.4 to 6.5, and OTP from 17.4 to 20.3, highlighting the urgency of applying the recommended security patches.

Affected Version(s)

OTP 5.10.4 < 7.0

OTP 1.0

OTP 17.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Jonatan Männchen / EEF
Ingela Anderton Andin
.