Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-32144

Erlang/OTP accepts a forged OCSP designated responder certificate

Technology

Erlang/OTP

CVSS Score

7.4 / 10.0

Affected Versions

OTP 27.0 and later, before 27.3.4.10 and 28.4.2 (public_key)

Upstream Fix

OTP 27.3.4.10, 28.4.2

Published

April 7, 2026

OSSeva Coverage

Fixed upstream

Description

public_key:pkix_ocsp_validate/5 checks that a designated OCSP responder certificate names the CA as issuer and carries the OCSPSigning extended key usage, but not that the CA signed it. An attacker who can intercept OCSP responses can use a self-signed certificate with a matching issuer name to forge responses that mark revoked certificates as valid. NVD scores it 7.4; the EEF's CVSS 4.0 score is 7.6.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 27.0 and later, before 27.3.4.10 and 28.4.2 (public_key), you need this patch. Book a discovery call to get covered.