Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the…
提示
摘要
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes …
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://cna.erlef.org/cves/CVE-2026-89422.html
- https://github.com/erlang/otp/commit/21b8a1b0ad0adf200682b3854bc50114ab2b8c62
- https://github.com/erlang/otp/commit/98c66c858113949c4262d26cd7d426c4b09d2b35
- https://github.com/erlang/otp/commit/afec5156361bb50d3607c7c1a453c19b9149b324
- https://github.com/erlang/otp/commit/fd1d9d07fc92ec0d59f96dfb66182195882bb7dd
- https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875
- https://osv.dev/vulnerability/EEF-CVE-2026-89422
- https://www.erlang.org/doc/system/versions.html#order-of-versions
时间线
- nvd_ingest NVD