erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP

cve CVE-2026-48855 2 sources, 2 claims · Watch

Red Hat writes:
erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP the claim

What it is to other things

affectserlang/erlang\/otp
NVD
affectserlang/erlang\/ssh
NVD
made_byerlang
NVD

In words only, so not counted until a person confirms one:

affectserlang/otp
NVD says “Erlang · OTP”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "ssh",
            "packageURL": "pkg:otp/ssh?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "5.2.11.8",
                    "status": "unaffected"
                  },
                  {
                    "at": "5.5.2.1",
                    "status": "unaffected"
                  },
                  {
                    "at": "6.0.1",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "status": "affected",
                "version": "08225797f7ef943d0c82a1d9dd6650d94ca2580d",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "83A78B2F-66C5-4840-9F31-3A0143B36705",
                "versionEndExcluding": "5.2.11.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "468A97BF-9BB0-4318-A6E9-CF69EFE385B7",
                "versionEndExcluding": "5.5.2.1",
                "versionStartIncluding": "5.5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0BF9A1F8-83F5-4BEB-A972-3AF5B15947EF",
                "versionEndExcluding": "6.0.1",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.\n\nThe SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.\n\nThe information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown."
      }
    ],
    "id": "CVE-2026-48855",
    "lastModified": "2026-09-24T21:17:14.143",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48855",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:22:16.684743Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:09.680",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48855.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/08225797f7ef943d0c82a1d9dd6650d94ca2580d"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/8f4224a0d2676b0653d2c71a889a956e8c2c62d6"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48855"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat4.3
receipt
Source
Red Hat
Its words
4.3
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48855",
  "CWE": "CWE-59",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487603",
  "bugzilla_description": "erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48855.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-59
receipt
Source
Red Hat
Its words
CWE-59
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48855",
  "CWE": "CWE-59",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487603",
  "bugzilla_description": "erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48855.json",
  "severity": "moderate"
}
—
Packages
packages
Red Haterlang27-main-27.3.4.17-1.hum1
receipt
Source
Red Hat
Its words
erlang27-main-27.3.4.17-1.hum1
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48855",
  "CWE": "CWE-59",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487603",
  "bugzilla_description": "erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48855.json",
  "severity": "moderate"
}
—
Product
product
NVDOTP
receipt
Source
NVD
Its words
OTP
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-09-29 17:49 UTCOTP
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "ssh",
            "packageURL": "pkg:otp/ssh?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "5.2.11.8",
                    "status": "unaffected"
                  },
                  {
                    "at": "5.5.2.1",
                    "status": "unaffected"
                  },
                  {
                    "at": "6.0.1",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "status": "affected",
                "version": "08225797f7ef943d0c82a1d9dd6650d94ca2580d",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "83A78B2F-66C5-4840-9F31-3A0143B36705",
                "versionEndExcluding": "5.2.11.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "468A97BF-9BB0-4318-A6E9-CF69EFE385B7",
                "versionEndExcluding": "5.5.2.1",
                "versionStartIncluding": "5.5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0BF9A1F8-83F5-4BEB-A972-3AF5B15947EF",
                "versionEndExcluding": "6.0.1",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.\n\nThe SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.\n\nThe information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown."
      }
    ],
    "id": "CVE-2026-48855",
    "lastModified": "2026-09-24T21:17:14.143",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48855",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:22:16.684743Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:09.680",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48855.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/08225797f7ef943d0c82a1d9dd6650d94ca2580d"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/8f4224a0d2676b0653d2c71a889a956e8c2c62d6"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48855"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48855",
  "CWE": "CWE-59",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487603",
  "bugzilla_description": "erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP",
  "cvss3_score": "4.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48855.json",
  "severity": "moderate"
}
medium
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "ssh",
            "packageURL": "pkg:otp/ssh?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "5.2.11.8",
                    "status": "unaffected"
                  },
                  {
                    "at": "5.5.2.1",
                    "status": "unaffected"
                  },
                  {
                    "at": "6.0.1",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "status": "affected",
                "version": "08225797f7ef943d0c82a1d9dd6650d94ca2580d",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "83A78B2F-66C5-4840-9F31-3A0143B36705",
                "versionEndExcluding": "5.2.11.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "468A97BF-9BB0-4318-A6E9-CF69EFE385B7",
                "versionEndExcluding": "5.5.2.1",
                "versionStartIncluding": "5.5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0BF9A1F8-83F5-4BEB-A972-3AF5B15947EF",
                "versionEndExcluding": "6.0.1",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.\n\nThe SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.\n\nThe information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown."
      }
    ],
    "id": "CVE-2026-48855",
    "lastModified": "2026-09-24T21:17:14.143",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48855",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:22:16.684743Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:09.680",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48855.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/08225797f7ef943d0c82a1d9dd6650d94ca2580d"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/8f4224a0d2676b0653d2c71a889a956e8c2c62d6"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48855"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDErlang
receipt
Source
NVD
Its words
Erlang
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-09-29 17:49 UTCErlang
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "ssh",
            "packageURL": "pkg:otp/ssh?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "5.2.11.8",
                    "status": "unaffected"
                  },
                  {
                    "at": "5.5.2.1",
                    "status": "unaffected"
                  },
                  {
                    "at": "6.0.1",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "ssh_sftpd"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssh/src/ssh_sftpd.erl"
            ],
            "programRoutines": [
              {
                "name": "ssh_sftpd:handle_op/4"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "status": "affected",
                "version": "08225797f7ef943d0c82a1d9dd6650d94ca2580d",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "8f4224a0d2676b0653d2c71a889a956e8c2c62d6",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "83A78B2F-66C5-4840-9F31-3A0143B36705",
                "versionEndExcluding": "5.2.11.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "468A97BF-9BB0-4318-A6E9-CF69EFE385B7",
                "versionEndExcluding": "5.5.2.1",
                "versionStartIncluding": "5.5",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0BF9A1F8-83F5-4BEB-A972-3AF5B15947EF",
                "versionEndExcluding": "6.0.1",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.\n\nThe SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.\n\nThe information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown."
      }
    ],
    "id": "CVE-2026-48855",
    "lastModified": "2026-09-24T21:17:14.143",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48855",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:22:16.684743Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:09.680",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48855.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/08225797f7ef943d0c82a1d9dd6650d94ca2580d"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/8f4224a0d2676b0653d2c71a889a956e8c2c62d6"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Mitigation",
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48855"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP
zetlyn/cve-redhat · 2026-06-10
cvss 4.3 cwe CWE-59 packages erlang27-main-27.3.4.17-1.hum1 severity moderate source
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /. The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown.
zetlyn/cve-nvd · 2026-06-10
cvss 6.5 product OTP status Modified vendor Erlang source