A critical vulnerability tracked as CVE-2026-55953 affects Erlang/OTP SSL clients using TLS 1.2 and earlier as well as DTLS, allowing an on-path attacker to bypass server authentication and intercept supposedly secure sessions. The flaw occurs because the client does not verify that the cipher suite selected by the server was actually offered in the ClientHello, enabling an attacker to force an anonymous cipher suite and complete the handshake without certificate validation or hostname checking. Once the connection is established, the attacker can read and modify traffic; TLS 1.3 is not affected because it already performs the required cipher-suite membership check.
The issue affects Erlang/OTP from OTP 17.0 up to the patched releases 27.3.4.15, 28.5.0.4, and 29.0.4, with corresponding SSL fixes in 11.2.12.11, 11.6.0.4, and 11.7.4. Erlang/OTP maintainers addressed the bug in July with code changes to ssl_handshake.erl that add a pre-TLS 1.3 client cipher-suite validation check and trigger a fatal illegal_parameter alert if the negotiated suite was not advertised by the client. The vulnerability carries a CVSS 4.0 score of 9.1 and is classified under CWE-757.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On July 3, 2026, Erlang/OTP added a pre-TLS 1.3 client-side check to verify that the server-selected cipher suite was actually offered by the client, aborting the handshake with an illegal_parameter alert if not. The fix was committed in Erlang/OTP branches associated with releases OTP-27.3.4.15 and OTP-29.0.4.
CVE-2026-55953 was publicly documented as a critical Erlang/OTP SSL vulnerability affecting TLS 1.2 and earlier and DTLS clients, allowing an on-path attacker to force an anonymous cipher suite and bypass server authentication. The disclosure identified fixed Erlang/OTP releases 27.3.4.15, 28.5.0.4, and 29.0.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcecna.erlef.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.