CVE-2026-89422 is a TLS 1.3 authentication-bypass vulnerability in the Erlang/OTP ssl application. A malicious responding peer can include an unsolicited pre_shared_key extension in its ServerHello. Affected clients incorrectly mark the handshake as resumed solely from the extension's presence, despite not having offered a PSK. The handshake uses the normal non-PSK key schedule with a no-PSK value, but follows the resumption state path directly to Finished, bypassing certificate-processing states. As a result, certificate path validation, verify_fun handling, hostname verification, partial-chain validation, CRL checking, and OCSP stapling are skipped. The flaw affects default TLS 1.3 client configurations in OTP releases from 22.2 through versions before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical TLS 1.3 server-impersonation vulnerability in Erlang/OTP's ssl application. A malicious peer can send an unsolicited pre_shared_key extension in ServerHello, causing affected TLS clients to treat the connection as resumed and bypass server-certificate authentication.
Critical Erlang/OTP ssl TLS 1.3 server-authentication bypass. An attacker acting as the destination host or positioned on path can send an unsolicited pre_shared_key extension in ServerHello, cause the client to treat the handshake as resumed, bypass certificate and hostname validation, and impersonate the intended server with access to all traffic keys.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.