CVE-2026-32144
Erlang/OTP accepts a forged OCSP designated responder certificate
Technology
Erlang/OTP
CVSS Score
7.4 / 10.0
Affected Versions
OTP 27.0 and later, before 27.3.4.10 and 28.4.2 (public_key)
Upstream Fix
OTP 27.3.4.10, 28.4.2
Published
April 7, 2026
OSSeva Coverage
Fixed upstream
Description
public_key:pkix_ocsp_validate/5 checks that a designated OCSP responder certificate names the CA as issuer and carries the OCSPSigning extended key usage, but not that the CA signed it. An attacker who can intercept OCSP responses can use a self-signed certificate with a matching issuer name to forge responses that mark revoked certificates as valid. NVD scores it 7.4; the EEF's CVSS 4.0 score is 7.6.
Is your Erlang/OTP deployment affected?
If you're running OTP 27.0 and later, before 27.3.4.10 and 28.4.2 (public_key), you need this patch. Book a discovery call to get covered.