Erlang/OTP users were urged to patch after multiple vulnerabilities were disclosed across the platform, including high-severity flaws that can crash BEAM nodes or exhaust resources during normal protocol handling. CVE-2026-59251 affects public_key certificate path validation, where a crafted X.509 chain can trigger exponential certificate policy tree growth during a TLS handshake and consume CPU and memory until the VM fails. CVE-2026-58227 affects the ssl application, where mutually cross-signed certificates can cause unbounded recursion while rebuilding incomplete TLS or DTLS peer chains, allowing an unauthenticated attacker to crash either servers or clients before authentication completes.
A separate high-severity flaw, CVE-2026-54890, impacts the erts External Term Format decoder used by binary_to_term/1, binary_to_term/2, and enif_binary_to_term(), where an integer underflow in BIT_BINARY_EXT decoding can trigger near-2^64 memory allocation and terminate the entire Erlang VM. National cyber authorities in Canada and Italy published advisories directing administrators to review Erlang security bulletins and update affected releases, while the Italian notice said the broader disclosure set includes additional Erlang/OTP issues spanning denial of service, remote code execution, authentication bypass, and security feature bypass. Fixed versions cited across the disclosures include 27.3.4.15, 28.5.0.4, and 29.0.4.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Italy's national cybersecurity agency reported multiple newly identified Erlang/OTP vulnerabilities, including one critical and four high-severity issues affecting components such as ssl, tls_handshake, pubkey_policy_tree, and erts. The agency recommended updating vulnerable products in line with vendor security bulletins.
The Canadian Centre for Cyber Security published advisory AV26-750 warning that Erlang is affected by vulnerabilities in certain OTP versions and recommending that administrators review the Erlang/OTP security advisory and apply updates. The notice states the affected versions as of July 27, 2026.
Security advisories describe patched Erlang/OTP releases 27.3.4.15, 28.5.0.4, and 29.0.4 for multiple flaws, including certificate policy tree growth in public_key, recursive certificate-chain handling in ssl, and an integer underflow in erts ETF decoding. The issues can allow remote denial of service or VM crashes in affected versions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.