Wiz Agents & Workflows are here

CVE-2022-37026
Erlang OTP vulnerability analysis and mitigation

Overview

A Client Authentication Bypass vulnerability (CVE-2022-37026) was discovered in Erlang/OTP affecting versions before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2. The vulnerability impacts SSL, TLS, and DTLS implementations in the Erlang runtime system. This security issue was disclosed in September 2022 (NVD, Ubuntu).

Technical details

The vulnerability affects servers that request client certification by setting the option {verify, verify_peer}. It occurs in certain client-certification situations where the TLS client certificate validation during the TLS handshake is not properly implemented. The issue received a CVSS 3.1 Base Score of 9.8 (Critical), indicating a high-severity vulnerability with network attack vector, low attack complexity, and no required privileges or user interaction (Ubuntu).

Impact

The vulnerability allows remote attackers to bypass client authentication mechanisms in servers using the SSL application either directly or indirectly through other applications such as inets (httpd) or cowboy. This affects the security of systems requiring client certificate verification (Erlang Forums, Debian).

Mitigation and workarounds

The vulnerability has been fixed in Erlang/OTP versions 23.3.4.15, 24.3.4.2, and 25.0.2 or later. Users are recommended to upgrade to these patched versions or later releases on their respective tracks. The fix was implemented through several commits that enhanced the handling of unexpected messages in the SSL implementation (Erlang Forums).

Additional resources


SourceThis report was generated using AI

Related Erlang OTP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48041HIGH7.1
  • CBL MarinerCBL Mariner
  • erlang-diameter
NoYesSep 11, 2025
CVE-2025-48040MEDIUM6.9
  • CBL MarinerCBL Mariner
  • erlang-dialyzer
NoYesSep 11, 2025
CVE-2025-48039MEDIUM5.3
  • CBL MarinerCBL Mariner
  • erlang-diameter
NoYesSep 11, 2025
CVE-2025-48038MEDIUM5.3
  • CBL MarinerCBL Mariner
  • erlang26-dialyzer
NoYesSep 11, 2025
CVE-2026-21620LOW2.3
  • CBL MarinerCBL Mariner
  • erlang-debugger
NoYesFeb 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management