Entity Authentication Vulnerability in Erlang/OTP SSL
CVE-2026-89422

9.3CRITICAL

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-89422?

A Key Exchange without Entity Authentication vulnerability exists in Erlang/OTP ssl that allows an attacker to impersonate the intended server during a TLS 1.3 client connection. This occurs due to a flaw in the handling of the pre_shared_key extension in the ServerHello message. The client is misled into completing the handshake without validating the server's certificate, posing risks as the peer can hold no certificate, private key, or session context. This vulnerability bypasses essential certificate checks including path validation, hostname verification, and OCSP stapling, making the default client configurations particularly susceptible.

Affected Version(s)

OTP 22.2

OTP 9.5

OTP 21b8a1b0ad0adf200682b3854bc50114ab2b8c62

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Milad Nasr / Anthropic
Luna Tong / Anthropic
Ingela Andin
.