๐Ÿ” CVE Alert

CVE-2025-48039

UNKNOWN 0.0

Unverified Paths can Cause Excessive Use of System Resources

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
36th

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.

CWE CWE-770 CWE-400
Vendor erlang
Product otp
Published Sep 11, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for erlang otp

Be the first to know when new unknown vulnerabilities affecting erlang otp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Erlang / OTP
3.0.1 < *
Erlang / OTP
17.0 < * 07b8f441ca711f9812fad9e9115bab3c3aa92f79 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/erlang/otp/security/advisories/GHSA-rr5p-6856-j7h8 cna.erlef.org: https://cna.erlef.org/cves/CVE-2025-48039.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2025-48039 erlang.org: https://www.erlang.org/doc/system/versions.html#order-of-versions github.com: https://github.com/erlang/otp/pull/10155 github.com: https://github.com/erlang/otp/commit/c242e6458967e9514bea351814151695807a54ac github.com: https://github.com/erlang/otp/commit/043ee3c943e2977c1acdd740ad13992fd60b6bf0

Credits

Jakub Witczak Ingela Andin