erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation

cve CVE-2026-48860 2 sources, 2 claims · Watch

Red Hat writes:
erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation the claim

What it is to other things

affectserlang/erlang\/otp
NVD
affectserlang/erlang\/ssl
NVD
made_byerlang
NVD

In words only, so not counted until a person confirms one:

affectserlang/otp
NVD says “Erlang · OTP”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "26.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "ssl",
            "packageURL": "pkg:otp/ssl?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "11.2.12.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.6.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.7.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "11.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "0209a6df65d605552b378273027b3968b35f26b4",
                "status": "affected",
                "version": "7a08c5507862a7011568506d0c17b1fdef30bee4",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F891113-4D35-4AB8-AA44-F3B6FC784F48",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0CA14B60-463E-40CC-912B-C7F2CA378F10",
                "versionEndExcluding": "11.2.12.9",
                "versionStartIncluding": "11.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3B27962B-3148-468A-973A-9C1564E41697",
                "versionEndExcluding": "11.6.0.2",
                "versionStartIncluding": "11.6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "39203B38-8145-4DC7-9624-2EB224B7E6AA",
                "versionEndExcluding": "11.7.2",
                "versionStartIncluding": "11.7",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist.\n\nThe inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the subnet mask comparison to always succeed regardless of the actual remote address. Any holder of a CA-signed TLS certificate can therefore bypass the LAN restriction and gain full Erlang distribution access to the node, including rpc:call/4 and code:load_binary/3.\n\nThis vulnerability is associated with program file lib/ssl/src/inet_tls_dist.erl.\n\nThis issue affects OTP from OTP 26.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssl from 11.0 before 11.2.12.9, 11.6.0.2, and 11.7.2."
      }
    ],
    "id": "CVE-2026-48860",
    "lastModified": "2026-09-24T21:17:14.607",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "ADJACENT",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48860",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:23:08.922807Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.503",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48860.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/0209a6df65d605552b378273027b3968b35f26b4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/7a08c5507862a7011568506d0c17b1fdef30bee4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48860"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          },
          {
            "lang": "en",
            "value": "CWE-1025"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat6.8
receipt
Source
Red Hat
Its words
6.8
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 12:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48860",
  "CWE": "CWE-303",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487597",
  "bugzilla_description": "erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation",
  "cvss3_score": "6.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48860.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-303
receipt
Source
Red Hat
Its words
CWE-303
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 12:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48860",
  "CWE": "CWE-303",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487597",
  "bugzilla_description": "erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation",
  "cvss3_score": "6.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48860.json",
  "severity": "moderate"
}
—
Packages
packages
Red Haterlang27-main-27.3.4.17-1.hum1
receipt
Source
Red Hat
Its words
erlang27-main-27.3.4.17-1.hum1
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 12:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48860",
  "CWE": "CWE-303",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487597",
  "bugzilla_description": "erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation",
  "cvss3_score": "6.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48860.json",
  "severity": "moderate"
}
—
Product
product
NVDOTP
receipt
Source
NVD
Its words
OTP
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
2026-09-29 17:49 UTCOTP
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "26.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "ssl",
            "packageURL": "pkg:otp/ssl?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "11.2.12.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.6.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.7.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "11.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "0209a6df65d605552b378273027b3968b35f26b4",
                "status": "affected",
                "version": "7a08c5507862a7011568506d0c17b1fdef30bee4",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F891113-4D35-4AB8-AA44-F3B6FC784F48",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0CA14B60-463E-40CC-912B-C7F2CA378F10",
                "versionEndExcluding": "11.2.12.9",
                "versionStartIncluding": "11.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3B27962B-3148-468A-973A-9C1564E41697",
                "versionEndExcluding": "11.6.0.2",
                "versionStartIncluding": "11.6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "39203B38-8145-4DC7-9624-2EB224B7E6AA",
                "versionEndExcluding": "11.7.2",
                "versionStartIncluding": "11.7",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist.\n\nThe inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the subnet mask comparison to always succeed regardless of the actual remote address. Any holder of a CA-signed TLS certificate can therefore bypass the LAN restriction and gain full Erlang distribution access to the node, including rpc:call/4 and code:load_binary/3.\n\nThis vulnerability is associated with program file lib/ssl/src/inet_tls_dist.erl.\n\nThis issue affects OTP from OTP 26.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssl from 11.0 before 11.2.12.9, 11.6.0.2, and 11.7.2."
      }
    ],
    "id": "CVE-2026-48860",
    "lastModified": "2026-09-24T21:17:14.607",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "ADJACENT",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48860",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:23:08.922807Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.503",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48860.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/0209a6df65d605552b378273027b3968b35f26b4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/7a08c5507862a7011568506d0c17b1fdef30bee4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48860"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          },
          {
            "lang": "en",
            "value": "CWE-1025"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 12:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-48860",
  "CWE": "CWE-303",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487597",
  "bugzilla_description": "erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation",
  "cvss3_score": "6.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-48860.json",
  "severity": "moderate"
}
medium
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "26.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "ssl",
            "packageURL": "pkg:otp/ssl?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "11.2.12.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.6.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.7.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "11.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "0209a6df65d605552b378273027b3968b35f26b4",
                "status": "affected",
                "version": "7a08c5507862a7011568506d0c17b1fdef30bee4",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F891113-4D35-4AB8-AA44-F3B6FC784F48",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0CA14B60-463E-40CC-912B-C7F2CA378F10",
                "versionEndExcluding": "11.2.12.9",
                "versionStartIncluding": "11.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3B27962B-3148-468A-973A-9C1564E41697",
                "versionEndExcluding": "11.6.0.2",
                "versionStartIncluding": "11.6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "39203B38-8145-4DC7-9624-2EB224B7E6AA",
                "versionEndExcluding": "11.7.2",
                "versionStartIncluding": "11.7",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist.\n\nThe inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the subnet mask comparison to always succeed regardless of the actual remote address. Any holder of a CA-signed TLS certificate can therefore bypass the LAN restriction and gain full Erlang distribution access to the node, including rpc:call/4 and code:load_binary/3.\n\nThis vulnerability is associated with program file lib/ssl/src/inet_tls_dist.erl.\n\nThis issue affects OTP from OTP 26.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssl from 11.0 before 11.2.12.9, 11.6.0.2, and 11.7.2."
      }
    ],
    "id": "CVE-2026-48860",
    "lastModified": "2026-09-24T21:17:14.607",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "ADJACENT",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48860",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:23:08.922807Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.503",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48860.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/0209a6df65d605552b378273027b3968b35f26b4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/7a08c5507862a7011568506d0c17b1fdef30bee4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48860"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          },
          {
            "lang": "en",
            "value": "CWE-1025"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDErlang
receipt
Source
NVD
Its words
Erlang
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
2026-09-29 17:49 UTCErlang
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "26.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "ssl",
            "packageURL": "pkg:otp/ssl?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "11.2.12.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.6.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "11.7.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "11.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "inet_tls_dist"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "lib/ssl/src/inet_tls_dist.erl"
            ],
            "programRoutines": [
              {
                "name": "inet_tls_dist:check_ip/1"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "0209a6df65d605552b378273027b3968b35f26b4",
                "status": "affected",
                "version": "7a08c5507862a7011568506d0c17b1fdef30bee4",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F891113-4D35-4AB8-AA44-F3B6FC784F48",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0CA14B60-463E-40CC-912B-C7F2CA378F10",
                "versionEndExcluding": "11.2.12.9",
                "versionStartIncluding": "11.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3B27962B-3148-468A-973A-9C1564E41697",
                "versionEndExcluding": "11.6.0.2",
                "versionStartIncluding": "11.6",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/ssl:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "39203B38-8145-4DC7-9624-2EB224B7E6AA",
                "versionEndExcluding": "11.7.2",
                "versionStartIncluding": "11.7",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist.\n\nThe inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the subnet mask comparison to always succeed regardless of the actual remote address. Any holder of a CA-signed TLS certificate can therefore bypass the LAN restriction and gain full Erlang distribution access to the node, including rpc:call/4 and code:load_binary/3.\n\nThis vulnerability is associated with program file lib/ssl/src/inet_tls_dist.erl.\n\nThis issue affects OTP from OTP 26.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssl from 11.0 before 11.2.12.9, 11.6.0.2, and 11.7.2."
      }
    ],
    "id": "CVE-2026-48860",
    "lastModified": "2026-09-24T21:17:14.607",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "ADJACENT",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-48860",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:23:08.922807Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.503",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-48860.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/0209a6df65d605552b378273027b3968b35f26b4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/erlang/otp/commit/7a08c5507862a7011568506d0c17b1fdef30bee4"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48860"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          },
          {
            "lang": "en",
            "value": "CWE-1025"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation
zetlyn/cve-redhat · 2026-06-10
cvss 6.8 cwe CWE-303 packages erlang27-main-27.3.4.17-1.hum1 severity moderate source
Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the subnet mask comparison to always succeed regardless of the actual remote address. Any holder of a CA-signed TLS certificate can therefore bypass the LAN restriction and gain full Erlang distribution access to the node, including rpc:call/4 and code:load_binary/3. This vulnerability is associated with program file lib/ssl/src/inet_tls_dist.erl. This issue affects OTP from OTP 26.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssl from 11.0 before 11.2.12.9, 11.6.0.2, and 11.7.2.
zetlyn/cve-nvd · 2026-06-10
cvss 6.5 product OTP status Modified vendor Erlang source