Erlang/OTP 29.0.1 patch release fixes multiple bugs and two CVEs across six applications. Security fixes include: corrected basic constraint path validation per RFC 5280 (CVE-2026-42789), and removal of legacy hostname verification fallback to subject common name in favor of RFC 9525 compliance (CVE-2026-42790, a potential incompatibility). OCSP responder certificate expiration is now properly checked before acceptance. Other fixes address a compiler bug that could invert boolean expression values, a compiler crash with native records, incorrect native record comparison results in the runtime system, SCTP peeloff IPv6 socket option inheritance, and a snmpm_usm crash on unknown user/engineID combinations.
Table of contents
POTENTIAL INCOMPATIBILITIEScompiler-10.0.1erts-17.0.1kernel-11.0.1public_key-1.21.1snmp-5.20.4ssl-11.7.1Thanks to1.1K Impressions