Improper Input Validation in Erlang/OTP Stdlib
CVE-2026-59696
What is CVE-2026-59696?
A vulnerability exists in the Erlang/OTP standard library that allows remote attackers to degrade the availability of affected applications. The issue arises from improper validation of the specified quantity in input data, specifically through the parsing of URIs. When an attacker supplies a URI with an excessively long port component, the system may take an extended amount of time to convert the string into a binary integer, consuming substantial processing resources. This vulnerability affects all applications parsing user-supplied URIs through the documented interface with no additional safeguards, thus exposing numerous applications across various environments to potential disruptions.
Affected Version(s)
OTP 21.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
