CVE-2026-59251
Erlang/OTP certificate policy tree grows exponentially during path validation
Technology
Erlang/OTP
CVSS Score
7.5 / 10.0
Affected Versions
OTP 26.2 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (public_key)
Upstream Fix
OTP 27.3.4.15, 28.5.0.4, 29.0.4
Published
July 27, 2026
OSSeva Coverage
Fixed upstream
Description
During RFC 5280 policy processing in public_key:pkix_path_validation/3 the policy tree has no upper bound, so a chain with many policies per certificate grows it exponentially. A remote, unauthenticated peer can send such a chain in a TLS handshake to pin schedulers and exhaust the node's memory. NVD scores it 7.5; the EEF's CVSS 4.0 score is 8.7.
Is your Erlang/OTP deployment affected?
If you're running OTP 26.2 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (public_key), you need this patch. Book a discovery call to get covered.