CVE security advisories and vulnerability history for OTP by Erlang.
28
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
2
Public exploits
With known exploit
6.5
Avg CVSS
2017–2026
Last updated
Overview
Erlang OTP has 28 published CVE records since 2017, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 2 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Erlang OTP, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of Erlang OTP's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High8
Medium10
Low2
6 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of Erlang OTP's CVEs is confirmed exploited in the wild.
Public exploits
2
2 of Erlang OTP's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every Erlang OTP version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about Erlang OTP vulnerabilities.
How many CVEs does Erlang OTP have?
Erlang OTP has 28 published CVE records since 2017.
How many Erlang OTP CVEs are in CISA KEV?
Yes — 1 of Erlang OTP's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for Erlang OTP vulnerabilities?
Yes — 2 of Erlang OTP's CVEs have a known public exploit.
Which versions of Erlang OTP are affected?
656 distinct Erlang OTP versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in Erlang OTP CVEs?
Erlang OTP's CVEs most often map to these CWE weakness types: CWE-295 (Improper Certificate Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-789 (Memory Allocation with Excessive Size Value).
How many critical Erlang OTP vulnerabilities are there?
Erlang OTP has 2 critical and 8 high-severity CVEs.
What is the average severity of Erlang OTP CVEs?
The average CVSS base score across Erlang OTP's scored CVEs is 6.5.