Resource Allocation Vulnerability in Erlang/OTP's Public Key Certificate Validation
CVE-2026-59251
8.7HIGH
What is CVE-2026-59251?
A vulnerability in Erlang/OTP's public_key certificate path validation can lead to Denial of Service. This occurs due to an unbounded growth of the certificate policy tree during the processing of crafted X.509 certificate chains. An attacker can send a specially designed certificate chain during the TLS handshake, causing the policy tree to expand exponentially. This results in memory exhaustion and potential crashes of the Erlang VM. The issue affects multiple versions of OTP and public_key, enabling exploitation during standard TLS connections. Immediate remediation through available patches is highly recommended.
Affected Version(s)
OTP 1.15
OTP 26.2
OTP 9d1dda7bad5a64b58c10a1554751689e94131a73
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukas Backström
Jakub Witczak
Michał Wąsowski
