CVE-2026-89422 affects Erlang/OTP's TLS 1.3 session-resumption handling, where a client that detects the pre_shared_key extension in ServerHello treats the handshake as resumed and proceeds from EncryptedExtensions directly to the finished-message stage. This path bypasses the normal certificate and certificate-verification processing used for full TLS handshakes.
The issue maps to CWE-322: Key Exchange without Entity Authentication. An attacker able to impersonate or intercept a target TLS endpoint could exploit missing peer-identity validation during PSK resumption to conduct man-in-the-middle or server-impersonation attacks, potentially exposing credentials and application data despite use of encryption. Organizations using Erlang/OTP TLS 1.3 should identify affected deployments and apply vendor remediation or restrict vulnerable resumption paths when available.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-89422 was published for an Erlang/OTP TLS 1.3 client flaw in which an unsolicited pre_shared_key extension can cause certificate validation to be bypassed, enabling server impersonation. The issue affects OTP releases from 22.2 before 27.3.4.18, 28.5.0.7, and 29.1.1; those releases contain fixes.
CLASP originally submitted the CWE-322 entry, “Key Exchange without Entity Authentication,” to the CWE catalog.
Erlang/OTP changed its TLS 1.3 client to reject server-selected pre_shared_key identities that were not offered by the client with a fatal illegal_parameter alert. The patch also delays resumption handling until PSK validation succeeds and adds regression coverage for rogue certificate-less servers.
MITRE’s CWE Content Team updated CWE-322 in CWE 4.19, including detection factors, relationships, and weakness ordinalities.
Erlang OTP added preliminary client-side TLS 1.3 session-resumption support using PSK detection in ServerHello. The resumption path transitions from EncryptedExtensions to wait_finished and bypasses the normal certificate-processing path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceosv.dev
Open sourcecna.erlef.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.