CVE Tools

Otp

62 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Otp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Otp CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Otp CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-021
2025-031
2025-041
2025-051
2025-061
2025-070
2025-080
2025-094
2025-100
2025-110
2025-120
2026-010
2026-021
2026-033
2026-044
2026-053
2026-067
2026-0714
2026-080
2026-0919

Severity

How the 62 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical38%
  • High1128%
  • Medium2255%
  • Low410%

Latest CVEs

The 15 most recently published vulnerabilities affecting Otp.

  1. CVE-2026-65634Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder—
  2. CVE-2026-68956SSH daemon allocates unbounded idle session channels, bypassing max_channels—
  3. CVE-2026-89422TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension—
  4. CVE-2026-69664httpd parks a request worker indefinitely on a malformed chunk size sent after the headers—
  5. CVE-2026-70409eldap does not bound the port component of a referral URL before integer conversion—
  6. CVE-2026-70405snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields—
  7. CVE-2026-66835httpd mod_auth directory protection bypassed by a doubled slash in the request path—
  8. CVE-2026-73270httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems—
  9. CVE-2026-75538A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer—
  10. CVE-2026-74994inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth—
  11. CVE-2026-74835inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception—
  12. CVE-2026-73812inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length—
  13. CVE-2026-73276inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i—
  14. CVE-2026-66357inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation—
  15. CVE-2026-59696uri_string does not bound the port component of a URI before integer conversion—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store