Resource Exhaustion Vulnerability in Erlang/OTP SSH
CVE-2026-68956

7.1HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-68956?

A vulnerability in the SSH implementation of Erlang/OTP can be exploited by an authenticated remote attacker to exhaust node memory. This issue occurs when multiple session channels are opened without being properly handled, leading to a substantial accumulation of memory resources consumed. The vulnerability arises from insufficient checks in the ssh_connection handler, allowing for potentially limitless channel creation, which may culminate in node termination and affect all applications running on the node. The vulnerability impacts various versions of Erlang/OTP, specifically those from OTP 17.0 prior to OTP 27.3.4.18, as well as other specified versions of SSH.

Affected Version(s)

OTP 17.0

OTP 3.0.1

OTP 84adefa331c4159d432d22840663c38f155cd4c1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Wąsowski / Ericsson
Jakub Witczak / Ericsson
.