CVE-2026-28810
Last modified
CVE-2026-28810 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization. Response validation relies almost entirely on this ID, making DNS cache poisoning practical for an attacker who can observe one query or predict the next ID. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization. Response validation relies almost entirely on this ID, making DNS cache poisoning practical for an attacker who can observe one query or predict the next ID. This conflicts with RFC 5452 recommendations for mitigating forged DNS answers. inet_res is intended for use in trusted network environments and with trusted recursive resolvers. Earlier documentation did not clearly state this deployment assumption, which could lead users to deploy the resolver in environments where spoofed DNS responses are possible. This vulnerability is associated with program files lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl. This issue affects OTP from OTP 17.0 before OTP 28.4.2, OTP 27.3.4.10 and OTP 26.2.5.19, corresponding to kernel from 3.0 before 10.6.2, 10.2.7.4 and 9.2.4.11.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Erlang | Erlang\/Otp | >= 17.0, < 26.2.5.19 |
| Erlang | Erlang\/Otp | >= 27.0, < 27.3.4.10 |
| Erlang | Erlang\/Otp | >= 28.0, < 28.4.2 |
References
- https://cna.erlef.org/cves/CVE-2026-28810.htmlThird Party Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-28810Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-28810?
How severe is CVE-2026-28810?
How do I fix CVE-2026-28810?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-28805OpenSTAManager is an open source management software for tec…8.8
- CVE-2026-28806Improper Authorization vulnerability in nerves-hub nerves_hu…8.8
- CVE-2026-28807Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2026-28808Incorrect Authorization vulnerability in Erlang OTP (inets m…9.8
- CVE-2026-28809XML External Entity (XXE) vulnerability in esaml (and its fo…5.3
- CVE-2026-2881A vulnerability has been found in D-Link DWR-M960 1.01.07. T…8.8
- CVE-2026-28811Debug Messages Revealing Unnecessary Information in Apache J…7.5
- CVE-2026-28812UserManager lack of checks allows impersonation in Apache JS…9.8
- CVE-2026-28813Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijackin…8.8
- CVE-2026-28814Arbitrary Wiki Markup rendering due to lack of authenticatio…7.5
- CVE-2026-28815A remote attacker can supply a short X-Wing HPKE encapsulate…7.5
- CVE-2026-28816A path handling issue was addressed with improved validation…4
Are you affected by CVE-2026-28810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
