CVE-2026-28810Disclosure(erlang / erlang\/otp)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization. Response validation relies almost entirely on this ID, making DNS cache poisoning practical for an attacker who can observe one query or predict the next ID. This conflicts with RFC 5452 recommendations for mitigating forged DNS answers. inet_res is intended for use in trusted network environments and with trusted recursive resolvers. Earlier documentation did not clearly state this deployment assumption, which could lead users to deploy the resolver in environments where spoofed DNS responses are possible. This vulnerability is associated with program files lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl. This issue affects OTP from OTP 17.0 before OTP 28.4.2, OTP 27.3.4.10 and OTP 26.2.5.19, corresponding to kernel from 3.0 before 10.6.2, 10.2.7.4 and 9.2.4.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-340

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erlang\/otp

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
erlang\/otp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-19: 104-0704-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28810 Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver… https://www.cve.org/CVERecord?id=CVE-2026-28810

    Post summary

    The text announces CVE-2026-28810 in Erlang/OTP, detailing its exploit potential for DNS cache poisoning, but does not mention PoC, exploitation, or mitigation.

    00010252
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28810 DNS Cache Poisoning via Predictable Transaction IDs in Erlang/OTP Kernel https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28810

    Post summary

    The text announces a DNS cache poisoning vulnerability in Erlang/OTP caused by predictable transaction IDs, with technical details but no evidence of exploitation, fixes, or PoC.

    0000067
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apperlangerlang\/otp---

Explore more