LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-58227

erlang · erlang\/otp

Published
CVSS7.5
Severityhigh
WeaknessCWE-674
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certificate_chain/5, which walks issuer relationships via ssl_certificate:do_certificate_chain/7 with no cycle detection and no depth limit. When the peer supplies two mutually cross-signed certificates in unordered form (A issues B, B issues A), the issuer lookup alternates between the two certificates and the pair of functions recurses indefinitely, growing the call stack and chain accumulator without bound. An unauthenticated remote attacker can sen

References

← Back to the CVE Tracker

Our coverage of CVE-2026-58227

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-58227.