Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-59250

Erlang/OTP megaco flex scanner buffer overflow from an oversized property name

Technology

Erlang/OTP

CVSS Score

8.3 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (megaco)

Upstream Fix

OTP 27.3.4.15, 28.5.0.4, 29.0.4

Published

July 27, 2026

OSSeva Coverage

Fixed upstream

Description

The megaco flex scanner C driver formats an attacker-controlled property name into a fixed 512-byte buffer with an unchecked sprintf. A single text-encoded H.248/Megaco message with an oversized property name corrupts driver memory, which can crash the node and might allow code execution. No authentication is needed.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (megaco), you need this patch. Book a discovery call to get covered.