CVE-2026-55950Disclosure(erlang / erlang\/otp)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch erlang erlang\/otp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_packet_demux gen_server process to route incoming UDP datagrams to the correct connection handler. When a DTLS client reconnects rapidly from the same source address and port (sending multiple ClientHello messages in quick succession), a race condition in the demux's internal gb_trees key-value store causes a {key_exists, {old, Client}} crash, terminating the demux process. Because the demux is shared across all DTLS associations on that listener, its crash immediately kills every active DTLS session, not just the attacker's. The attack is pre-authentication: the attacker only needs to send UDP datagrams containing valid ClientHello messages from the same source IP and port before the intermediate DOWN monitor message is processed by the gen_server. No credentials, no completed handshake, and no special configuration are required, and the crash can be repeated indefinitely to create a persistent denial of service for all clients of that listener. This vulnerability is associated with program file lib/ssl/src/dtls_packet_demux.erl. This issue affects OTP from OTP 25.3 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 10.9 before 11.7.3, 11.6.0.3 and 11.2.12.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erlang\/otp
  • erlang\/ssl

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
erlang\/otperlang\/ssl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-17: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 107-0307-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-031
Disclosure1
2026-07-171
General1
Full discourse2 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Erlang ❗ CVE-2026-55952 ❗ CVE-2026-55950 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-erlang/ https://t.co/NwBqjKLwTn

    Post summary

    The tweet simply announces two Erlang CVEs with links for more information, but provides no technical, exploit, or remediation details.

    00000202
    6.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Erlang/OTP DTLS Listener DoS via TOCTOU Race in dtls_packet_demux (CVE-2026-55950) A DTLS server listener in Erlang/OTP's ssl app routes all incoming UDP datagrams through a single shared dtls_packet_demux gen_server. A TOCTOU race in its internal gb_trees store can be triggered when a client reconnects rapidly from the same source IP and port (multiple ClientHello messages in quick succession), causing a {key_exists, {old, Client}} crash that terminates the demux process. Because the demux is shared across every DTLS association on that listener, its crash kills all active DTLS sessions, not just the attacker's. The attack is fully pre-authentication - no credentials, no completed handshake, no special config - and can be repeated indefinitely for persistent denial of service. 👉Upgrade to Erlang/OTP 29.0.3, 28.5.0.3, or 27.3.4.14 (ssl 11.7.3 / 11.6.0.3 / 11.2.12.10).

    Post summary

    The post discloses CVE‑2026‑55950, a DTLS listener DoS triggered by a TOCTOU race, and recommends upgrading to specific Erlang/OTP releases for remediation.

    0000086
    236 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apperlangerlang\/otp---
Apperlangerlang\/ssl---

Explore more