LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-23943

erlang · erlang\/otp

Published
CVSS5.3
Severitymedium
WeaknessCWE-409
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Description

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: * zlib: Activates immediately after key exchange, enabling unauthenticated attacks * zlib@openssh.com: Activates post-authentication, enabling authenticated attacks Each SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exh

References

← Back to the CVE Tracker

Our coverage of CVE-2026-23943

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-23943.