FlawAtlas
Search the atlas
CVE-2026-23943 Moderate

Pre-auth SSH DoS via unbounded zlib inflate

## Summary Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh\_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: \* zlib: Activates immediately after key exchange, enabling unauthenticated attacks \* [email protected]: Activates post-authentication, enabling authenticated attacks Each SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exhaust available memory, causing OOM kills in memory-constrained environments. This vulnerability is associated with program files lib/ssh/src/ssh\_transport.erl and program routines ssh\_transport:decompress/2, ssh\_transport:handle\_packet\_part/4. This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14. ## Workaround Best workaround - Disable all compression: {preferred\_algorithms, \[{compression, \['none'\]}\]} Alternative mitigations (less secure): \* Disable only pre-auth zlib compression (authenticated users can still exploit via [email protected]): {modify\_algorithms, \[{rm, \[{compression, \['zlib'\]}\]}\]} \* Limit concurrent sessions (reduces attack surface but does not prevent exploitation): {max\_sessions, N} % Cap total concurrent sessions (default is infinity) ## Configuration The SSH server or client must advertise zlib or [email protected] compression. Both are enabled by default. With zlib, the attack is pre-authentication; with [email protected], authentication is required first.

Exploit probability 0.6%
Published March 13, 2026
Required by Not available
Last source change July 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

75 explicit affected versions

Unknown Unknown

82 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-23943

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: * zlib: Activates immediately after key exchange, enabling unauthenticated attacks * [email protected]: Activates post-authentication, enabling authenticated attacks Each SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exhaust available memory, causing OOM kills in memory-constrained environments. This vulnerability is associated with program files lib/ssh/src/ssh_transport.erl and program routines ssh_transport:decompress/2, ssh_transport:handle_packet_part/4. This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14.

View original source
Open Source Vulnerabilities EEF-CVE-2026-23943

## Summary Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh\_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: \* zlib: Activates immediately after key exchange, enabling unauthenticated attacks \* [email protected]: Activates post-authentication, enabling authenticated attacks Each SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exhaust available memory, causing OOM kills in memory-constrained environments. This vulnerability is associated with program files lib/ssh/src/ssh\_transport.erl and program routines ssh\_transport:decompress/2, ssh\_transport:handle\_packet\_part/4. This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14. ## Workaround Best workaround - Disable all compression: {preferred\_algorithms, \[{compression, \['none'\]}\]} Alternative mitigations (less secure): \* Disable only pre-auth zlib compression (authenticated users can still exploit via [email protected]): {modify\_algorithms, \[{rm, \[{compression, \['zlib'\]}\]}\]} \* Limit concurrent sessions (reduces attack surface but does not prevent exploitation): {max\_sessions, N} % Cap total concurrent sessions (default is infinity) ## Configuration The SSH server or client must advertise zlib or [email protected] compression. Both are enabled by default. With zlib, the attack is pre-authentication; with [email protected], authentication is required first.

View original source

05 / REFERENCES

Further evidence