Back to blog

// OSSeva Blog

Security

Erlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them

Matt Reynolds11 min read

The short answer

Three Erlang/OTP major releases get security fixes today: OTP 27, 28 and 29. According to endoflife.date, OTP 27 is supported until 20 May 2027, OTP 28 until 20 May 2028 and OTP 29 until 11 May 2029. OTP 26 reached end of life on 26 May 2026, and its last release, 26.2.5.21, shipped that day. OTP 25 ended in May 2025 with 25.3.2.21, and OTP 24 in May 2024 with 24.3.4.17. No Erlang/OTP advisory published since June 2026 names an OTP 26 fix. That includes CVE-2026-89422, a TLS 1.3 client authentication bypass rated 9.3, and it matters for RabbitMQ because public RabbitMQ 3.13 releases cannot run on anything newer than OTP 26.

OTP release lines

In practice the project patches the three newest major releases. A new major ships each May, and the oldest of the three drops out of support around the same time.

ReleaseFirst releaseLatest or final patchSecurity support
OTP 29May 202629.1.1Until 11 May 2029
OTP 28May 202528.5.0.7Until 20 May 2028
OTP 27May 202427.3.4.18Until 20 May 2027
OTP 26May 202326.2.5.21 (26 May 2026)Ended 26 May 2026
OTP 25May 202225.3.2.21 (May 2025)Ended 17 May 2025
OTP 24May 202124.3.4.17 (April 2024)Ended 10 May 2024

Erlang advisories are published by the Erlang Ecosystem Foundation, the CVE numbering authority for Erlang/OTP, and give an affected range per OTP release and per application (ssl, ssh, inets, erts, public_key and so on). Many 2026 records, including all of September's, are in NVD's Deferred status, so for those NVD shows only the EEF's CVSS 4.0 score.

The 2026 advisory waves

Each row is one set of patch releases. The CVEs listed are those rated 7.0 or higher by NVD or by the EEF; each wave also fixed medium and low issues, and patch sets with nothing rated 7.0 or higher are left out.

NVD publishedFixed inCVEs rated 7.0 or higherOTP 26
13 March 202626.2.5.18, 27.3.4.9, 28.4.1CVE-2026-23941 (inets httpd request smuggling)Patched
7 April 202626.2.5.19, 27.3.4.10, 28.4.2CVE-2026-28808 (inets httpd auth bypass for CGI scripts), CVE-2026-32144 (OCSP designated responder accepted without a signature check, OTP 27 and later)Patched
27 May 202626.2.5.21, 27.3.4.12, 28.5.0.1, 29.0.1CVE-2026-42790 (TLS hostname verification bypasses name constraints), CVE-2026-42789 (public_key accepts a non-CA certificate as an intermediate issuer)Patched, the last time
10 June 202627.3.4.13, 28.5.0.2, 29.0.2CVE-2026-49759 (SCTP stack buffer overflow crashes the VM), CVE-2026-48860 (the LAN check for Erlang distribution over TLS is never enforced), CVE-2026-48856 (httpc sends the Authorization header to cross-origin redirect targets)No fix
2 July 202627.3.4.14, 28.5.0.3, 29.0.3CVE-2026-55952 (TLS 1.3 session ticket denial of service), CVE-2026-55950 (DTLS denial of service)No fix
27 July 202627.3.4.15, 28.5.0.4, 29.0.4CVE-2026-55953 (TLS 1.2 and DTLS clients accept an unoffered anonymous cipher suite), CVE-2026-59251, CVE-2026-58227, CVE-2026-59250 (megaco flex scanner buffer overflow), CVE-2026-54890, CVE-2026-42792 (epmd stops after running out of file descriptors)No fix
1 September 202627.3.4.17, 28.5.0.6, 29.0.6Four inets httpd denial of service flaws (CVE-2026-69664, CVE-2026-70399, CVE-2026-71380, CVE-2026-74835), three httpd request smuggling flaws (CVE-2026-73276, CVE-2026-66357, CVE-2026-73812), two mod_auth bypasses (CVE-2026-66835, CVE-2026-73270), the httpc header flaw CVE-2026-55951 and the inet driver overflow CVE-2026-75538No fix
22 September 202627.3.4.18, 28.5.0.7, 29.1.1CVE-2026-89422, CVE-2026-65634, CVE-2026-68956No fix

OTP 26 missed every row from June onward, and almost all of those advisories list OTP 26 inside the affected range.

Notable Erlang/OTP CVEs by release line

NVD has analysed some of these records and scored them itself with CVSS 3.1, often differently from the EEF's CVSS 4.0 score. Where both exist, the table shows both.

CVEApplicationIssueCVSS27 / 28 / 29 fix2625 and 24
CVE-2025-32433sshUnauthenticated remote code execution in the SSH server; in the KEV catalogue10.0 (GitHub)27.3.3; 28 and 29 not affected26.2.5.1125.3.2.20; 24 not patched
CVE-2026-89422sslTLS 1.3 client skips server authentication on an unsolicited PSK9.3 (EEF)27.3.4.18, 28.5.0.7, 29.1.1Not patchedNot patched (from 22.2)
CVE-2026-28808inetshttpd directory authentication does not apply to CGI scripts served through ScriptAlias9.8 (NVD); 8.3 (EEF)27.3.4.10, 28.4.226.2.5.19Not patched
CVE-2026-23941inetshttpd request smuggling through duplicate Content-Length headers9.4 (NVD); 7.0 (EEF)27.3.4.9, 28.4.126.2.5.18Not patched
CVE-2026-55953sslTLS 1.2 and DTLS clients accept an anonymous cipher suite they never offered, bypassing certificate checks7.4 (NVD); 9.1 (EEF)27.3.4.15, 28.5.0.4, 29.0.4Not patchedNot patched
CVE-2026-49759ertsStack buffer overflow in SCTP error cause parsing crashes the VM8.2 (NVD); 8.8 (EEF)27.3.4.13, 28.5.0.2, 29.0.2Not patchedNot patched
CVE-2026-42790public_keyTLS hostname verification falls back to the subject common name and bypasses DNS name constraints8.1 (NVD); 7.6 (EEF)27.3.4.12, 28.5.0.1, 29.0.126.2.5.21Not patched (from 19.3)
CVE-2026-65634asn1Quadratic-time OID decoding during a TLS handshake8.2 (EEF)27.3.4.18, 28.5.0.7, 29.1.1Not patchedNot patched
CVE-2026-75538ertsLength overflow in the inet driver in {packet,4} mode writes past the receive buffer8.2 (EEF)27.3.4.17, 28.5.0.6, 29.0.6Not patchedNot patched
CVE-2026-59251public_keyCertificate policy tree grows exponentially during path validation7.5 (NVD); 8.7 (EEF)27.3.4.15, 28.5.0.4, 29.0.4Not patchedNot affected (from 26.2)
CVE-2026-58227sslMutually cross-signed certificates in a chain cause unbounded recursion and crash the node7.5 (NVD); 8.7 (EEF)27.3.4.15, 28.5.0.4, 29.0.4Not patchedNot patched (from 23.2)
CVE-2026-55952sslMismatched PSK identity and binder lists crash a TLS 1.3 server using session tickets7.5 (NVD); 8.2 (EEF)27.3.4.14, 28.5.0.3, 29.0.3Not patchedNot patched (from 22.2)
CVE-2026-54890ertsbinary_to_term crashes on crafted BIT_BINARY_EXT input7.5 (NVD); 8.2 (EEF)27.3.4.15, 28.5.0.4, 29.0.4Not affectedNot affected
CVE-2022-37026sslClient authentication bypass in certain client certificate setups9.8 (NVD)Not affectedNot affected25.0.2, 24.3.4.2

"Not patched" means the release is inside the affected range and no patch on it carries the fix.

September 2026: CVE-2026-89422 and the rest of the month

CVE-2026-89422 is a flaw in the TLS 1.3 client. If the ServerHello carries a pre_shared_key extension the client never offered, the client treats the handshake as a resumption and skips the server certificate entirely, so a peer with no certificate and no key can pose as the intended server. The default client configuration is affected, and clients limited to TLS 1.2 are not. It affects OTP 22.2 and later and is fixed in 27.3.4.18, 28.5.0.7 and 29.1.1. Our write-up of CVE-2026-89422 on OTP 26 covers where RabbitMQ acts as a TLS client.

NVD lists 19 Erlang/OTP CVEs published between 1 and 22 September 2026: CVE-2026-89422, which the EEF rates critical, 13 rated high and 5 medium. Sixteen came on 1 September with 27.3.4.17, 28.5.0.6 and 29.0.6, and ten of those are in inets httpd, the web server that ships with OTP. One of them, CVE-2026-73812, is a gap left by the March fix for CVE-2026-23941: since then httpd rejects duplicate Content-Length headers, but it still accepts a request that carries both Transfer-Encoding and Content-Length. The other three came on 22 September with 27.3.4.18, 28.5.0.7 and 29.1.1. None of the 19 has an OTP 26 fix.

CVE-2025-32433, the SSH remote code execution

CVE-2025-32433 (10.0) lets an unauthenticated attacker run code on any node that runs the Erlang/OTP SSH server, through a flaw in how the server handles SSH protocol messages. CISA added it to the Known Exploited Vulnerabilities catalogue on 9 June 2025. It is fixed in 25.3.2.20, 26.2.5.11 and 27.3.3, and OTP 24 and older got no fix. The 10.0 is the GitHub CNA score on NVD.

It only matters where the ssh application runs as a daemon. RabbitMQ does not use Erlang SSH, so a broker is not exposed through it, but other Erlang and Elixir software may be, and NVD's record lists Cisco ConfD and Network Services Orchestrator among the affected products. Check for it with application:which_applications() on each node.

Which RabbitMQ versions pin which OTP

RabbitMQ supports a narrow band of OTP releases per patch version, so the broker version decides which runtime fixes you can take. The ranges below are from RabbitMQ's Erlang version requirements page.

RabbitMQMinimum OTPMaximum OTPNewest runtime it can use
3.8.29 to 3.8.35, 3.9.15 to 3.9.27, 3.10.0 to 3.10.423.2 to 24.224.3OTP 24, end of life
3.9.28, 3.9.29, 3.10.5 to 3.10.2523.2 to 24.3.4.825.2 or 25.3.xOTP 25, end of life
3.11.0 to 3.11.2825.025.3.xOTP 25, end of life
3.12.0 to 3.12.1325.026.0.x to 26.2.xOTP 26, end of life
3.13.0 to 3.13.726.026.2.xOTP 26, end of life
4.0.1 to 4.0.326.226.2.xOTP 26, end of life
4.0.4 to 4.0.9, 4.1.x, 4.2.0 to 4.2.8, 4.3.0 to 4.3.226.227.xOTP 27
4.2.9, 4.2.10, 4.3.3 to 4.3.527.027.xOTP 27
4.3.627.028.xOTP 28; the same page says OTP 29 is supported from 4.3.6

RabbitMQ's notes add that OTP 28 is partly supported from 4.2.0, for brand new clusters only, because Khepri clusters upgraded from OTP 27 can hit a known issue in mixed-version clusters. Every public 3.x release is capped at an OTP release that is now out of support, so on 3.x no supported runtime exists with the 2026 fixes from June onward. On 4.x the runtime is OTP 27 for most releases, which is supported until 20 May 2027. RabbitMQ and Erlang version compatibility covers the pairs in more detail.

What a broker exposes depends on what it runs, not just the OTP version. RabbitMQ's HTTP listeners run on Cowboy rather than inets httpd, so the inets httpd CVEs do not reach them, and it does not use the ssh application. The TLS, public_key, asn1 and erts flaws are a different matter: any TLS listener, and any outbound TLS connection from a Shovel, Federation link, LDAP server or OAuth 2 key fetch, goes through the OTP code those advisories fix.

What each line gets

OTP 29, 28 and 27

Each has been patched in every advisory since it was released. 27.3.4.18, 28.5.0.7 and 29.1.1 are the releases to run. OTP 27 is the next to leave support, on 20 May 2027, and most RabbitMQ 4.x releases list 27.x as their maximum, so check now that your broker release supports OTP 28.

OTP 26

OTP 26 ended on 26 May 2026 with 26.2.5.21, which carried the fixes for CVE-2026-42790 and CVE-2026-42789. Since then it has missed every advisory, including CVE-2026-89422 at 9.3 and CVE-2026-55953, a TLS 1.2 client flaw that NVD scores 7.4 and the EEF 9.1. See Erlang/OTP 26 end of life.

OTP 25

OTP 25 ended in May 2025. Its last fixes were for CVE-2025-32433 in 25.3.2.20 and the strict key exchange fix for CVE-2025-46712 in 25.3.2.21. It has missed the SSH and SFTP resource exhaustion fixes of September 2025, such as CVE-2025-48041, and everything since. See Erlang/OTP 25 end of life.

OTP 24

OTP 24 ended in May 2024 with 24.3.4.17. It has no fix for CVE-2025-32433, the KEV-listed SSH remote code execution, or for anything after it. See Erlang/OTP 24 end of life.

What to do on each line

  • 27, 28 and 29. Take each patch release. In 2026 the sets have come roughly once a month.
  • 26 under RabbitMQ 3.13 or 4.0.1 to 4.0.3. The runtime fix needs RabbitMQ 4.0.4 or later on OTP 27, or a patched OTP 26 build. No client TLS setting on an unpatched OTP 26 avoids both TLS client flaws: the CVE-2026-89422 advisory's workaround is to restrict clients to TLS 1.2, and the CVE-2026-55953 advisory's is to use TLS 1.3 only. Pick the one that fits each connection, and treat it as a stopgap.
  • 25 and 24. Confirm whether the ssh application runs. If it does, CVE-2025-32433 is the first thing to close.
  • Standalone Erlang and Elixir services. These usually move between OTP majors more easily than RabbitMQ does. Rebuild and test on OTP 27 or 28.

Where OSSeva fits

OSSeva ships patched Erlang/OTP 24, 25 and 26 builds with security fixes for the ssl, ssh, public_key and crypto applications backported, so a RabbitMQ 3.x cluster keeps a patched runtime while the move to 4.x is planned. They are available now on the Patch, Assure and Operate tiers. Assure adds the OTP upgrade path mapped against your broker estate, and Operate adds 24/7 BEAM monitoring with a 15-minute SLA and named Erlang engineers. See the Erlang/OTP support page and the Erlang/OTP end-of-life chart.

Tags

Erlang/OTPCVECVE-2026-89422CVE-2025-32433RabbitMQ

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.