Erlang security advisory (AV26-948)
Canadian Cyber Centre warns Erlang/OTP is affected by CVE-2026-65634 and CVE-2026-89422 and urges updates.
The Canadian Centre for Cyber Security published advisory AV26-948 stating that Erlang/OTP is affected by vulnerabilities tracked as CVE-2026-65634 and CVE-2026-89422. The notice lists multiple OTP release lines and commits that are fixed only in later builds, including 27.3.4.18, 28.5.0.7, and 29.1.1. Administrators are urged to review the linked erlang/otp GitHub security advisories and apply updates. No exploitation is described.
- Advisory AV26-948, dated September 22, 2026, covers Erlang/OTP.
- Cited identifiers are CVE-2026-65634 and CVE-2026-89422.
- Users are told to review the GitHub advisories and apply updates.
- The notice does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-656348.2—Unauthenticated DoS in Erlang/OTP asn1 OBJECT IDENTIFIER Decoder (CVE-2026-65634)published · Erlang OTP
- CVE-2026-894229.3—Key Exchange Impersonation in Erlang/OTP ssl (CVE-2026-89422)published · Erlang/OTP ssl
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|
Full article88 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-948
Date: September 22, 2026
As of September 22, 2026, Erlang is affected by vulnerabilities in the following product:
- OTP
- 17.0 Prior to 27.3.4.18
- 21b8a1b Prior to afec515, 98c66c8 and fd1d9d0
- 22.2 Prior to 27.3.4.18, 28.5.0.7 and 29.1.1
- 4.1.1 Prior to 5.2.11.13, 5.5.2.6 and 6.0.6
- 9.5 Prior to 11.2.12.13, 11.6.0.6 and 11.7.7
- Versions Prior to 84adefa
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/erlang-security-advisory-av26-948