FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20907-1 Not scored

Security update for erlang

This update for erlang fixes the following issues - CVE-2025-4748: improper limitation of a pathname may lead to path traversal (bsc#1244642). - CVE-2026-32147: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503). - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). - CVE-2026-42790: Name Constraints and Subject CommonName fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). - CVE-2026-42791: OCSP response verification in the `public_key` application does not check the validity period of the OCSP responder certificate and allows for OCSP response response forgery (bsc#1266448).

Exploit probability Not scored
Published June 5, 2026
Required by Not available
Last source change June 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 erlang

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20907-1

This update for erlang fixes the following issues - CVE-2025-4748: improper limitation of a pathname may lead to path traversal (bsc#1244642). - CVE-2026-32147: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503). - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). - CVE-2026-42790: Name Constraints and Subject CommonName fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). - CVE-2026-42791: OCSP response verification in the `public_key` application does not check the validity period of the OCSP responder certificate and allows for OCSP response response forgery (bsc#1266448).

View original source

05 / REFERENCES

Further evidence