PT-2026-96690 · Unknown+1 · Erlang/Otp+1
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Erlang/OTP versions 22.2 through 27.3.4.17
Erlang/OTP versions 28.0 through 28.5.0.6
Erlang/OTP versions 29.0 through 29.1.0
ssl versions 9.5 through 11.2.12.12
ssl versions 11.6.0 through 11.6.0.5
ssl versions 11.7.0 through 11.7.6
Description
A key exchange issue without entity authentication in the ssl module allows a peer responding to a TLS 1.3 client connection to impersonate the intended server. This occurs when a
pre shared key extension is present in the ServerHello that the client did not offer, causing the client to complete the handshake without validating the server certificate. Specifically, tls client connection 1 3:handle server hello/2 passes the extension to tls gen connection 1 3:handle resumption/2, which sets resumption = true without verifying if the client offered a PSK. Subsequently, tls handshake 1 3:get pre shared key/4 falls back to an all-zero value, and the maybe resumption/1 function routes directly to wait finished. This bypasses critical security checks including certificate path validation, verify fun, hostname verification, partial chain, CRL checking, and OCSP stapling. An attacker can intercept traffic, read sensitive data such as credentials and tokens, and forge responses. This affects any consumer of ssl:connect using TLS 1.3, including httpc over HTTPS and various database or messaging client libraries.Recommendations
Update Erlang/OTP to version 27.3.4.18, 28.5.0.7, or 29.1.1.
Update ssl to version 11.2.12.13, 11.6.0.6, or 11.7.7.
As a temporary workaround, restrict clients to TLS 1.2 by setting
{versions, ['tlsv1.2']} in the ssl options.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erlang/Otp
Ssl