Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-59251

Erlang/OTP certificate policy tree grows exponentially during path validation

Technology

Erlang/OTP

CVSS Score

7.5 / 10.0

Affected Versions

OTP 26.2 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (public_key)

Upstream Fix

OTP 27.3.4.15, 28.5.0.4, 29.0.4

Published

July 27, 2026

OSSeva Coverage

Fixed upstream

Description

During RFC 5280 policy processing in public_key:pkix_path_validation/3 the policy tree has no upper bound, so a chain with many policies per certificate grows it exponentially. A remote, unauthenticated peer can send such a chain in a TLS handshake to pin schedulers and exhaust the node's memory. NVD scores it 7.5; the EEF's CVSS 4.0 score is 8.7.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 26.2 and later, before 27.3.4.15, 28.5.0.4 and 29.0.4 (public_key), you need this patch. Book a discovery call to get covered.