Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-49760: CWE-121 Stack-based Buffer Overflow in Erlang OTP

0
Medium
VulnerabilityCVE-2026-49760cvecve-2026-49760cwe-121
Published: Wed Jun 10 2026 (06/10/2026, 14:35:36 UTC)
Source: CVE Database V5
Vendor/Project: Erlang
Product: OTP

Description

Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service. The companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug. This issue affects OTP from OTP 17.0 before 27.3.4.13, 28.5.0.2 and 29.0.2, corresponding to erl_interface from 3.7.16 before 5.5.2.1, 5.7.0.1 and 5.8.1.

CVSS v4.0

Score 6.9medium

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →cve
erl_interface
pkg:github/erl_interface
Affected versions
=3.7.16
GitHub Actionsmore threats →cve
erlang/otp
pkg:github/erlang/otp
Affected versions
>=84adefa331c4159d432d22840663c38f155cd4c1 <0bef277b2d39dc8babb9ceb4f5d0a456f3007111=17.0
CPE configurations
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/10/2026, 16:19:06 UTC

Technical Analysis

CVE-2026-49760 is a stack-based buffer overflow in the Erlang OTP erl_interface library's ei_s_print_term function. The function uses a fixed-size 2000-character stack buffer to format Erlang terms. When processing an encoded term with a very large integer whose encoded representation exceeds 2000 characters, the buffer overflows. The overflow bytes are limited to ASCII digits and uppercase hexadecimal letters, which restricts exploitation to denial of service rather than arbitrary code execution. The companion function ei_print_term, which outputs directly to a FILE, is not vulnerable. Affected versions include OTP 17.0 up to but not including 27.3.4.13, 28.5.0.2, and 29.0.2, and erl_interface versions 3.7.16 and later up to but not including 5.5.2.1, 5.7.0.1, and 5.8.1.

Potential Impact

The vulnerability allows an attacker to cause a denial of service by triggering a stack-based buffer overflow in the ei_s_print_term function when processing specially crafted large integer terms. The overflow is limited to certain ASCII characters, preventing code execution or other more severe impacts. There are no known exploits in the wild. The vulnerability requires local access (AV:L) and low complexity to exploit, with no privileges or user interaction needed.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should avoid processing untrusted large integer terms with the vulnerable ei_s_print_term function or use the non-vulnerable ei_print_term function where possible. Monitor Erlang OTP vendor advisories for updates and patches addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
EEF
Date Reserved
2026-06-01T13:45:22.449Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a298ad7c9170919df367457

Added to database: 6/10/2026, 4:03:35 PM

Last enriched: 6/10/2026, 4:19:06 PM

Last updated: 6/10/2026, 5:51:14 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses