Erlang/OTP 29.0.2 patch release fixes multiple security vulnerabilities and bugs across 12 applications. Security fixes include: a buffer overflow in SCTP parsing (erts, CVE-2026-49759) that could lead to RCE; a stack overflow in erl_interface for large integers (CVE-2026-49760); SSRF/FTP bounce attack via improper passive mode IP validation (ftp, CVE-2026-48858); credential leakage on HTTP redirects (inets, CVE-2026-48856); SSH timing-based username enumeration (CVE-2026-48859); SSH SFTP path disclosure (CVE-2026-48855); and TLS distribution LAN enforcement bypass (ssl, CVE-2026-48860). Non-security fixes include Dialyzer native record bugs, gen_tcp_socket option inheritance, stdlib record operation crashes, and SSH keep-alive race conditions.

6m read timeFrom erlangforums.com
Post cover image
Table of contents
dialyzer-6.0.1diameter-2.7.1erl_interface-5.8.1erts-17.0.2ftp-1.2.6inets-9.7.1kernel-11.0.2mnesia-4.26.1public_key-1.21.2ssh-6.0.1ssl-11.7.2stdlib-8.0.1tools-4.2.1Thanks to
133 Impressions