Buffer Overflow in Erlang/OTP Megaco Flex Scanner C Driver
CVE-2026-59250

8.3HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-59250?

A classic buffer overflow vulnerability exists in the Erlang/OTP Megaco flex scanner C driver, allowing a remote unauthenticated attacker to corrupt memory by sending a specially crafted H.248/Megaco message. The overflow occurs due to the improper handling of oversized property names, which can lead to arbitrary memory manipulation and potential remote code execution. The vulnerable code is executed prior to any authentication, making exploitation feasible for attackers with network access to the affected service. Certain build configurations may trigger runtime protections that terminate the process, resulting in a denial-of-service condition instead.

Affected Version(s)

OTP 3.17.1

OTP R13B03

OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 8704c8f550a11ed5f825e3c011ecb03565b79c4f

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Jakub Witczak
Micael Karlberg
.