Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-89422

Erlang/OTP TLS 1.3 client skips server authentication when the ServerHello carries an unsolicited PSK

Technology

Erlang/OTP

CVSS Score

9.3 / 10.0

Affected Versions

OTP 22.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssl 9.5 and later)

Upstream Fix

OTP 27.3.4.18, 28.5.0.7, 29.1.1

Published

September 22, 2026

OSSeva Coverage

Fixed upstream

Description

If the ServerHello contains a pre_shared_key extension the client never offered, the Erlang/OTP ssl client treats the handshake as a session resumption and skips the certificate states. Certificate path validation, verify_fun, hostname verification, CRL checks and OCSP stapling are all bypassed, and ssl:connect succeeds against a peer with no certificate, no private key and no prior session. The default client configuration is affected; clients restricted to TLS 1.2 are not.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 22.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssl 9.5 and later), you need this patch. Book a discovery call to get covered.