CVE-2022-37026
Critical
CVE-2022-37026
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
Exploit probability
1.2%
Published
September 21, 2022
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
66 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2022-37026
View original source
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
05 / REFERENCES
Further evidence
- https://erlangforums.com/c/erlang-news-announcements/91
- https://erlangforums.com/t/otp-25-1-released/1854
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37026.json
- https://github.com/erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15
- https://lists.debian.org/debian-lts-announce/2023/07/msg00012.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-37026