Erlang/OTP SSH Has Strict KEX Violations
Vulnerability Description
Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake hardening measures by allowing optional messages to be exchanged. This allows a Man-in-the-Middle attacker to inject these messages in a connection during the handshake. This issue has been patched in versions OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46712
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/erlang/otp/security/advisories/GHSA-934x-xq38-hhqf
- https://github.com/erlang/otp/commit/e4b56a9f4a511aa9990dd86c16c61439c828df83
- https://github.com/erlang/otp/releases/tag/OTP-25.3.2.21
- https://github.com/erlang/otp/releases/tag/OTP-26.2.5.12
- https://github.com/erlang/otp/releases/tag/OTP-27.3.4
More from erlang
View All →Affected Vendor
erlang
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.