CVE-2026-89422
Erlang/OTP TLS 1.3 client skips server authentication when the ServerHello carries an unsolicited PSK
Technology
Erlang/OTP
CVSS Score
9.3 / 10.0
Affected Versions
OTP 22.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssl 9.5 and later)
Upstream Fix
OTP 27.3.4.18, 28.5.0.7, 29.1.1
Published
September 22, 2026
OSSeva Coverage
Fixed upstream
Description
If the ServerHello contains a pre_shared_key extension the client never offered, the Erlang/OTP ssl client treats the handshake as a session resumption and skips the certificate states. Certificate path validation, verify_fun, hostname verification, CRL checks and OCSP stapling are all bypassed, and ssl:connect succeeds against a peer with no certificate, no private key and no prior session. The default client configuration is affected; clients restricted to TLS 1.2 are not.
Is your Erlang/OTP deployment affected?
If you're running OTP 22.2 and later, before 27.3.4.18, 28.5.0.7 and 29.1.1 (ssl 9.5 and later), you need this patch. Book a discovery call to get covered.