🔐 CVE Alert

CVE-2026-70409

UNKNOWN 0.0

eldap does not bound the port component of a referral URL before integer conversion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.

CWE CWE-1284
Vendor erlang
Product otp
Published Sep 1, 2026
Last Updated Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for erlang otp

Be the first to know when new unknown vulnerabilities affecting erlang otp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Erlang / OTP
17.0 < 27.3.4.17 28.0 < 28.5.0.6 29.0 < 29.0.6
Erlang / OTP
1.0.3 < 1.2.14.2 1.2.15 < 1.2.16.1 1.3 < 1.3.1
Erlang / OTP
d8dbf15de4fa1a08b9a05e7d8e08fdb025fe1dc3 < *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/erlang/otp/security/advisories/GHSA-9vgh-c8cm-m9p4 cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-70409.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-70409 erlang.org: https://www.erlang.org/doc/system/versions.html#order-of-versions github.com: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d github.com: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa

Credits

Eric Meadows-Jönsson Jonatan Männchen / EEF Peter Ullrich José Valim Konrad Pietrzak / Ericsson