CVE-2026-32144Disclosure(erlang / erlang\/otp)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder certificate's issuer name matches the CA's subject name and that the certificate has the OCSPSigning extended key usage. An attacker who can intercept or control OCSP responses can create a self-signed certificate with a matching issuer name and the OCSPSigning EKU, and use it to forge OCSP responses that mark revoked certificates as valid. This affects SSL/TLS clients using OCSP stapling, which may accept connections to servers with revoked certificates, potentially transmitting sensitive data to compromised servers. Applications using the public_key:pkix_ocsp_validate/5 API directly are also affected, with impact depending on usage context. This vulnerability is associated with program files lib/public_key/src/pubkey_ocsp.erl and program routines pubkey_ocsp:is_authorized_responder/3. This issue affects OTP from OTP 27.0 before OTP 28.4.2 and OTP 27.3.4.10, corresponding to public_key from 1.16 before 1.20.3 and 1.17.1.2, and ssl from 11.2 before 11.5.4 and 11.2.12.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erlang\/otp
  • erlang\/public_key
  • erlang\/ssl

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
erlang\/otperlang\/public_keyerlang\/ssl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-19: 104-0704-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-191
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32144 Improper Certificate Validation in Erlang OTP public_key OCSP Responder Authorization Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32144

    Post summary

    The snippet announces CVE‑2026‑32144, detailing improper certificate validation that allows an authorization bypass in Erlang OTP, but it does not provide PoCs, exploit code, active exploitation claims, or mitigation information.

    0000167
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32144 Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signatur… https://www.cve.org/CVERecord?id=CVE-2026-32144

    Post summary

    CVE-2026-32144 is an improper certificate validation vulnerability in Erlang OTP's public_key module that can allow an OCSP designated‑responder authorization bypass due to a missing signature.

    00000202
    57.2K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Apperlangerlang\/otp---
Apperlangerlang\/public_key---
Apperlangerlang\/ssl---

Explore more