erlang is vulnerable to Authentication Bypass
90
Critical Risk
Affected versions of the Erlang/OTP SSH server are vulnerable to unauthenticated remote code execution (RCE) due to a flaw in SSH protocol message handling. An attacker with network access can exploit this vulnerability to execute arbitrary commands without valid credentials. This can result in full system compromise, data manipulation, or denial of service. All versions using the Erlang/OTP SSH library are affected. As a temporary workaround, disable the SSH server or restrict access via firewall rules until a fixed version is applied.
You are affected if you are using a version that falls within the vulnerable range and you are running an SSH server via Erlang/OTP.
erlang is vulnerable to Authentication Bypass in versions 27.0.0 - 27.3.2, 26.0.0 - 26.2.5.10 and 25.0.0 - 25.3.2.19.
Upgrade the erlang library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant