Improper Input Validation in Erlang/OTP Stdlib
CVE-2026-59696

6.9MEDIUM

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-59696?

A vulnerability exists in the Erlang/OTP standard library that allows remote attackers to degrade the availability of affected applications. The issue arises from improper validation of the specified quantity in input data, specifically through the parsing of URIs. When an attacker supplies a URI with an excessively long port component, the system may take an extended amount of time to convert the string into a binary integer, consuming substantial processing resources. This vulnerability affects all applications parsing user-supplied URIs through the documented interface with no additional safeguards, thus exposing numerous applications across various environments to potential disruptions.

Affected Version(s)

OTP 21.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eric Meadows-Jönsson
Jonatan Männchen / EEF
Peter Ullrich
José Valim
Konrad Pietrzak / Ericsson
Ingela Anderton Andin
Dan Gudmundsson
John Högberg
Rickard Green
.