Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advert…
中危 CVSS 5.3
摘要
Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: * zlib: Activates immediately after key exchange, enabling unauthenticated attacks * zlib@o…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
Lint 边界警告 (1)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://www.erlang.org/doc/system/versions.html#order-of-versions
数据来源
- NVD DATABASE
原始链接
- https://cna.erlef.org/cves/CVE-2026-23943.html Vendor Advisory
- https://github.com/erlang/otp/commit/0c1c04b191f6ab940e8fcfabce39eb5a8a6440a4 Patch
- https://github.com/erlang/otp/commit/43a87b949bdff12d629a8c34146711d9da93b1b1 Patch
- https://github.com/erlang/otp/commit/93073c3bd338c60cd2bae715ce6a1d4ffc1a8fd3 Patch
- https://github.com/erlang/otp/security/advisories/GHSA-c836-qprm-jw9r Vendor Advisory
- https://osv.dev/vulnerability/EEF-CVE-2026-23943 Third Party Advisory
- https://www.erlang.org/doc/system/versions.html#order-of-versions Product
时间线
- nvd_ingest NVD