Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-65634

Erlang/OTP asn1 OBJECT IDENTIFIER decoder takes quadratic time on crafted input during TLS handshakes

Technology

Erlang/OTP

CVSS Score

8.2 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (asn1)

Upstream Fix

OTP 27.3.4.18, 28.5.0.7, 29.1.1

Published

September 22, 2026

OSSeva Coverage

Fixed upstream

Description

The asn1 OID decoders build each subidentifier in an unbounded integer, so work grows with the square of its length. A remote, unauthenticated attacker can send a crafted OID during the TLS handshake and tie up CPU to deny service.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (asn1), you need this patch. Book a discovery call to get covered.