← Vulnerability feed

Vulnerability record · CVE-2022-37026 · published 21 September 2022

CVE-2022-37026: Erlang\/otp vulnerability

Erlang · Erlang\/Otp

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 27.2%
9.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed9.8CVE-2016-10253Erlang\/otp memory buffer overflow vulnerabilityAn issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions…EPSS 1.5%9.1CVE-2026-55953Erlang\/otp vulnerabilityThe Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the su…EPSS 0.37%8.8CVE-2026-49759Erlang\/otp stack-based buffer overflow vulnerabilityStack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a c…EPSS 0.86%8.7CVE-2026-59251Erlang\/otp allocation without limits vulnerabilityAllocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial …EPSS 0.52%8.7CVE-2026-58227Erlang\/otp vulnerabilityThe Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl…EPSS 0.67%8.7CVE-2026-55950Erlang\/otp toctou race condition vulnerabilityTime-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacke…EPSS 0.68%8.3CVE-2026-28808Erlang\/inets incorrect authorization vulnerabilityIncorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2022-37026), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.