Two high-severity denial-of-service vulnerabilities in Erlang/OTP's ssl application allow unauthenticated remote attackers to disrupt secure listeners before authentication completes. CVE-2026-55950 affects the DTLS dtls_packet_demux component, where a time-of-check/time-of-use race condition can be triggered by rapidly sending multiple DTLS ClientHello messages from the same source IP address and port. Because the demultiplexing process is shared across DTLS associations on a listener, a successful crash terminates all active DTLS sessions on that listener rather than only the attacker's connection.
A second flaw, CVE-2026-55952, affects TLS 1.3 servers when malformed ClientHello pre-shared key data causes session ticket handling to crash after the software fails to validate that PSK identity and binder lists are the same length. A single crafted request can make TLS 1.3 unusable on an affected listener until the ssl application is restarted, while TLS 1.2 is not affected. Erlang/OTP maintainers released fixes in OTP 29.0.3, 28.5.0.3, and 27.3.4.14; the DTLS issue was addressed in a GitHub commit that changed logic in dtls_packet_demux.erl to safely handle existing keys during connection state transitions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-55952 was publicly documented as a high-severity denial-of-service vulnerability in Erlang/OTP's SSL application affecting TLS 1.3 servers. A malformed ClientHello pre-shared key extension can crash session ticket handling on an affected listener until the SSL application is restarted.
CVE-2026-55950 was publicly documented as a high-severity Erlang/OTP SSL vulnerability in dtls_packet_demux that lets an unauthenticated attacker crash the shared DTLS demux process and terminate all active DTLS sessions on a listener. Affected versions and fixed releases were identified in the disclosure.
A GitHub commit in the erlang/otp repository fixed a DTLS race condition in the SSL component that could be used for denial-of-service attacks against DTLS servers. The commit was made by IngelaAndin and tagged for OTP-29.0.3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceosv.dev
Open sourcegithub.com
Open sourcegithub.com
Open sourcecna.erlef.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.