Intel

AIKIDO-2025-10246

erlang is vulnerable to Authentication Bypass

Authentication BypassGHSA-37cp-fgq5-7wc2 Published Apr 17, 2025

90

Critical Risk

This Affects:

OSerlang
25.0.0 - 25.3.2.19
Fixed in 25.3.2.20
26.0.0 - 26.2.5.10
Fixed in 26.2.5.11
27.0.0 - 27.3.2
Fixed in 27.3.3
Are you affected? Scan for Free

TL;DR

Affected versions of the Erlang/OTP SSH server are vulnerable to unauthenticated remote code execution (RCE) due to a flaw in SSH protocol message handling. An attacker with network access can exploit this vulnerability to execute arbitrary commands without valid credentials. This can result in full system compromise, data manipulation, or denial of service. All versions using the Erlang/OTP SSH library are affected. As a temporary workaround, disable the SSH server or restrict access via firewall rules until a fixed version is applied.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you are running an SSH server via Erlang/OTP.

Background info

erlang is vulnerable to Authentication Bypass in versions 27.0.0 - 27.3.2, 26.0.0 - 26.2.5.10 and 25.0.0 - 25.3.2.19.

How to fix this

Upgrade the erlang library to the patch version.