Cycle Detection Flaw in Erlang/OTP SSL Application Affects Multiple Versions
CVE-2026-58227
8.7HIGH
What is CVE-2026-58227?
The Erlang/OTP SSL application is susceptible to a cycle detection flaw during TLS and DTLS handshake processes, specifically when handling incomplete certificate chains. An attacker can send a specially crafted certificate chain consisting of mutually cross-signed certificates, which leads to an infinite recursion, exhausting memory resources and ultimately crashing the BEAM node. This vulnerability affects both TLS and DTLS servers and clients and does not require authentication for exploitation.
Affected Version(s)
OTP 10.2
OTP 23.2
OTP addc42df113f8f15fc20e9dff45490b3ce0d3d6b
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukas Backström
Ingela Anderton Andin
Dan Gudmundsson
Jakub Witczak
John Högberg
