Exposición de Erlang

Programming languages
91
score de exposición
2120
sitios usan
1
en explotación
2
críticos
Análisis Vexday

Erlang apresenta um volume relativamente pequeno de CVEs catalogadas, mas os indicadores de risco são expressivos: a taxa de exploração ativa está 7,7 vezes acima da média geral do catálogo CISA KEV, sinalizando que vulnerabilidades nessa tecnologia tendem a ser alvos concretos, não apenas teóricos. Chama atenção o CVE-2025-32433, classificado como crítico e com escore EPSS de 0,9767 — indicando altíssima probabilidade de exploração ativa —, o que o torna prioridade imediata de remediação para qualquer ambiente que execute Erlang. O tipo de falha mais recorrente, CWE-295 (validação imprópria de certificados), sugere fragilidades estruturais no tratamento de TLS/SSL, com potencial impacto em confidencialidade e autenticidade de comunicações. O fato de 14 das 29 CVEs terem surgido nos últimos 90 dias reforça a necessidade de monitoramento contínuo e ciclos curtos de patching para esta tecnologia.

CVEs

43 resultados
CVE-2026-32147MEDIUMSFTP chroot bypass via path traversal in SSH_FXP_FSETSTATEPSS 0.4%CVE-2026-58227HIGHTLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainEPSS 0.4%CVE-2026-42790HIGHnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationEPSS 0.3%CVE-2026-48856HIGHhttpc leaks Authorization header to cross-origin redirect targetsEPSS 0.3%CVE-2026-54886MEDIUMSSH SFTP server denial of service via extended channel data infinite loopEPSS 0.3%CVE-2026-42789HIGHNon-CA certificate accepted as intermediate issuer in public_key path validationEPSS 0.3%CVE-2026-54890HIGHBEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decodingEPSS 0.3%CVE-2026-42791MEDIUMOCSP responder certificate validity period not checked in public_keyEPSS 0.3%CVE-2026-48855LOWSFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is ConfiguredEPSS 0.3%CVE-2026-28810MEDIUMPredictable DNS Transaction IDs Enable Cache Poisoning in Built-in ResolverEPSS 0.3%CVE-2026-53422LOWSFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured rootEPSS 0.3%CVE-2026-59251HIGHDenial of service via exponential certificate policy tree growth in path validationEPSS 0.3%CVE-2024-53846MEDIUMssl fails to validate incorrect extened key usageEPSS 0.3%CVE-2026-55953CRITICALTLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticationEPSS 0.2%CVE-2026-54887MEDIUMDTLS server cookie bypass during startup window due to empty initial cookie secretEPSS 0.2%CVE-2026-48858MEDIUMftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacksEPSS 0.2%CVE-2025-4748MEDIUMAbsolute path traversal in zip:unzip/1,2EPSS 0.2%CVE-2026-32144HIGHOCSP designated-responder authorization bypass via missing signature verificationEPSS 0.2%CVE-2026-48860HIGHDistribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_distEPSS 0.2%CVE-2026-47078MEDIUMRelative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypassEPSS 0.2%