Improper Input Validation in Erlang/OTP SNMP Affects Multiple Versions
CVE-2026-70405

6.3MEDIUM

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-70405?

Erlang/OTP's SNMP component features an improper validation of specified quantity in input, allowing remote attackers to potentially degrade the availability of affected systems. Specifically, the vulnerability exists due to a default infinite size limit in the decoding process of INTEGER inputs, which results in superlinear work as large values are processed. Multiple components utilize the unbounded decoding method, leading to the risk of unprocessed SNMP messages which can be exploited by attackers. This issue impacts several versions of Erlang/OTP, including specific subversions of the SNMP protocol from 4.25 to 5.20.5 and requires urgent attention to mitigate associated risks.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eric Meadows-Jönsson
Jonatan Männchen / EEF
Peter Ullrich
José Valim
Konrad Pietrzak / Ericsson
.