Cyber Resilience
← All news
Confirmed

Erlang security advisory (AV26-948)

Our takeCCC's AV26-948 flags multiple vulnerabilities in Erlang/OTP across many version branches. Update to a fixed release immediately if you run it yourself.
Sources (1)
What this means for you — Security leader:Apply the patches released in OTP 27.3.4.18, 28.5.0.7, 29.1.1 and the listed commits to all affected versions. Prioritize any internet-facing Erlang/OTP instances on your normal emergency change path.
What this means for you — Lean IT orgs:If you run any Erlang or OTP software (including versions listed in the advisory), update it to one of the fixed releases as soon as you can. Most small teams should check with their software vendor or hosting provider to see if they manage this for you.
What this means for you — MSP:Review all client environments for OTP versions 17–29 that match the affected ranges and schedule patching; flag any internet-exposed instances for immediate remediation across your book of business.
What this means for you — Researcher:Review the CCCS advisory and linked commits for impact on any Erlang-based tools or research infrastructure you maintain.