Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-68956

Erlang/OTP ssh daemon memory exhaustion through session channels that never get a handler

Technology

Erlang/OTP

CVSS Score

7.1 / 10.0

Affected Versions

OTP 18.1.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssh)

Upstream Fix

OTP 27.3.4.18, 28.5.0.7, 29.1.1

Published

September 22, 2026

OSSeva Coverage

Fixed upstream

Description

Session channels that never receive a shell, exec or subsystem request are stored but not counted against max_channels. An authenticated SSH user can keep opening them until the node runs out of memory.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 18.1.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssh), you need this patch. Book a discovery call to get covered.