Out-of-bounds Write Vulnerability in Erlang OTP by Erlang Solutions
CVE-2026-55737

5.1MEDIUM

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-55737?

An out-of-bounds write vulnerability exists in Erlang OTP that arises from a signed to unsigned conversion error and improper validation when decoding certain Erlang external term format (ETF) binaries. This flaw allows an attacker to craft malicious input that can cause heap corruption, ultimately leading to a virtual machine crash. Specifically, the vulnerability stems from a discrepancy in how the arity field is interpreted during the validation and decoding processes, allowing attackers to bypass runtime checks. This impacts various versions of OTP, requiring immediate attention from affected users.

Affected Version(s)

OTP 13.0

OTP 25.0

OTP ebcbb97b4ec223464cac3d94375739a248ddef6e

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nick Gunn
Kiko Fernandez-Reyes
Sverker Eriksson
.