CVE-2025-26618
Last modified
CVE-2025-26618 is a high-severity vulnerability rated 7/10 on the CVSS scale. Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang. Packet size is not verified properly for SFTP packets. As a result when multiple SSH packets (conforming to max SSH packet size) are received by ssh, they might be combined into an SFTP packet which will exceed the max allowed packet size and potentially cause large amount of memory to be allocated. Note that situation described above can only happen for successfully authenticated users after completing the SSH handshake. This issue has been patched in OTP versions 27.2.4, 26.2.5.9, and 25.3.2.18. There are no known workarounds for this vulnerability.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-26618?
How severe is CVE-2025-26618?
How do I fix CVE-2025-26618?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-26612WeGIA is an open source Web Manager for Institutions with a …9.8
- CVE-2025-26613WeGIA is an open source Web Manager for Institutions with a …9.8
- CVE-2025-26614WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-26615WeGIA is an open source Web Manager for Institutions with a …7.5
- CVE-2025-26616WeGIA is an open source Web Manager for Institutions with a …7.5
- CVE-2025-26617WeGIA is an open source Web Manager for Institutions with a …9.8
- CVE-2025-26619Vega is a visualization grammar, a declarative format for cr…6.1
- CVE-2025-2662A vulnerability was found in Project Worlds Online Time Tabl…8.8
- CVE-2025-26620Duende.AccessTokenManagement is a set of .NET libraries that…6.3
- CVE-2025-26621OpenCTI is an open source platform for managing cyber threat…6.8
- CVE-2025-26622vyper is a Pythonic Smart Contract Language for the EVM. Vyp…7.5
- CVE-2025-26623Exiv2 is a C++ library and a command-line utility to read, w…9.8
Are you affected by CVE-2025-26618?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
