Resource Exhaustion Vulnerability in Erlang/OTP SSH
CVE-2026-68956
What is CVE-2026-68956?
A vulnerability in the SSH implementation of Erlang/OTP can be exploited by an authenticated remote attacker to exhaust node memory. This issue occurs when multiple session channels are opened without being properly handled, leading to a substantial accumulation of memory resources consumed. The vulnerability arises from insufficient checks in the ssh_connection handler, allowing for potentially limitless channel creation, which may culminate in node termination and affect all applications running on the node. The vulnerability impacts various versions of Erlang/OTP, specifically those from OTP 17.0 prior to OTP 27.3.4.18, as well as other specified versions of SSH.
Affected Version(s)
OTP 17.0
OTP 3.0.1
OTP 84adefa331c4159d432d22840663c38f155cd4c1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
