Denial of Service Vulnerability in Erlang/OTP Product for TLS Handshake
CVE-2026-65634

8.2HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-65634?

An inefficiency in the OBJECT IDENTIFIER (OID) decoder within Erlang/OTP allows for remote unauthenticated attackers to exploit this flaw during the TLS handshake. By sending a specially crafted OID, attackers can trigger significant CPU usage, leading to denial of service. This vulnerability is particularly concerning for any Erlang service that parses peer TLS certificates, as it occurs before critical signature or trust chain verifications are applied. The vulnerable components reside in specific program files that manage OID decoding, which could impact various versions of Erlang/OTP.

Affected Version(s)

OTP 17.0

OTP 3.0

OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 0fe2c02fdc06fab1c63be9db1a7456993d20f838

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tynus2
Lukas Backström
John Högberg
.