Entity Authentication Vulnerability in Erlang/OTP SSL
CVE-2026-89422
What is CVE-2026-89422?
A Key Exchange without Entity Authentication vulnerability exists in Erlang/OTP ssl that allows an attacker to impersonate the intended server during a TLS 1.3 client connection. This occurs due to a flaw in the handling of the pre_shared_key extension in the ServerHello message. The client is misled into completing the handshake without validating the server's certificate, posing risks as the peer can hold no certificate, private key, or session context. This vulnerability bypasses essential certificate checks including path validation, hostname verification, and OCSP stapling, making the default client configurations particularly susceptible.
Affected Version(s)
OTP 22.2
OTP 9.5
OTP 21b8a1b0ad0adf200682b3854bc50114ab2b8c62
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
