๐Ÿ” CVE Alert

CVE-2025-48038

UNKNOWN 0.0

Unverified File Handles can Cause Excessive Use of System Resources

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
36th

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.

CWE CWE-770 CWE-400
Vendor erlang
Product otp
Published Sep 11, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for erlang otp

Be the first to know when new unknown vulnerabilities affecting erlang otp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Erlang / OTP
3.0.1 < *
Erlang / OTP
17.0 < * 07b8f441ca711f9812fad9e9115bab3c3aa92f79 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/erlang/otp/security/advisories/GHSA-pvj7-9652-7h9r cna.erlef.org: https://cna.erlef.org/cves/CVE-2025-48038.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2025-48038 erlang.org: https://www.erlang.org/doc/system/versions.html#order-of-versions github.com: https://github.com/erlang/otp/pull/10156 github.com: https://github.com/erlang/otp/commit/4e3bf86777ab3db7220c11d8ddabf15970ddd10a github.com: https://github.com/erlang/otp/commit/f09e0201ff701993dc24a08f15e524daf72db42f

Credits

Jakub Witczak Ingela Andin