๐Ÿ” CVE Alert

CVE-2025-48041

UNKNOWN 0.0

SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
36th

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.

CWE CWE-770 CWE-400
Vendor erlang
Product otp
Published Sep 11, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for erlang otp

Be the first to know when new unknown vulnerabilities affecting erlang otp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Erlang / OTP
3.0.1 < *
Erlang / OTP
17.0 < * 07b8f441ca711f9812fad9e9115bab3c3aa92f79 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/erlang/otp/security/advisories/GHSA-79c4-cvv7-4qm3 cna.erlef.org: https://cna.erlef.org/cves/CVE-2025-48041.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2025-48041 erlang.org: https://www.erlang.org/doc/system/versions.html#order-of-versions github.com: https://github.com/erlang/otp/pull/10157 github.com: https://github.com/erlang/otp/commit/5f9af63eec4657a37663828d206517828cb9f288 github.com: https://github.com/erlang/otp/commit/d49efa2d4fa9e6f7ee658719cd76ffe7a33c2401

Credits

Jakub Witczak Ingela Andin