CVE-2026-49759
8.2 · HIGHOverview
CVE-2026-49759 is a high-severity vulnerability affecting erlang erlang\/otp. It was published on June 10, 2026 and has a CVSS 3.1 base score of 8.2 (HIGH).
This vulnerability has a CVSS 3.1 base score of 8.2, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.
The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.
A crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is li
Remediation
Check the references section for vendor advisories and patches from erlang. Update erlang\/otp to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| erlang | erlang\/otp | >= 17.0, < 27.3.4.13 | Affected |
| erlang | erts | >= 6.0, < 15.2.7.9 | Affected |
References
Frequently Asked Questions
What is CVE-2026-49759?
CVE-2026-49759 is a high-severity vulnerability affecting erlang erlang\/otp. It was published on June 10, 2026 and has a CVSS 3.1 base score of 8.2 (HIGH).
How severe is CVE-2026-49759?
This vulnerability has a CVSS 3.1 base score of 8.2, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2026-49759?
Check the references section for vendor advisories and patches from erlang. Update erlang\/otp to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2026-49759?
CyberStrike's AI-powered security agents can automatically detect CVE-2026-49759 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related HIGH CVEs from 2026
View all →H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there
OpenProject is an open-source, web-based project management software. To enable the real time collab
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-st
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopwa
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypa
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that a
Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation funct
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 a