CVE-2026-49760: CWE-121 Stack-based Buffer Overflow in Erlang OTP
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service. The companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug. This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to erl_interface from 3.7.16 before 5.8.1, 5.7.0.1 and 5.5.2.1.
AI Analysis
Technical Summary
The vulnerability CVE-2026-49760 is a stack-based buffer overflow in the Erlang OTP erl_interface component, specifically in the ei_s_print_term function within lib/erl_interface/src/misc/ei_printterm.c. This function uses a fixed-size 2000-character stack buffer to format Erlang terms. When processing an encoded Erlang term containing a very large integer with an encoded representation exceeding 2000 characters, the buffer overflows. The overflowed bytes are limited to ASCII digits and uppercase hexadecimal letters, which constrains the exploitability to denial of service rather than arbitrary code execution. The companion function ei_print_term, which outputs directly to a FILE stream, does not exhibit this vulnerability. Affected versions include OTP releases from 17.0 before 29.0.2, 28.5.0.2, and 27.3.4.13, and erl_interface versions from 3.7.16 before 5.8.1, 5.7.0.1, and 5.5.2.1. No official patch or remediation level is provided in the available data.
Potential Impact
The buffer overflow can cause a denial of service condition due to stack corruption when processing specially crafted large integer terms. Exploitation is limited to denial of service because the overflowed data is restricted to ASCII characters 0-9 and A-F, preventing arbitrary code execution or other more severe impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided, users should monitor Erlang OTP vendor advisories for updates. Avoid using the vulnerable function ei_s_print_term with untrusted or excessively large encoded terms as a temporary mitigation.
CVE-2026-49760: CWE-121 Stack-based Buffer Overflow in Erlang OTP
Description
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service. The companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug. This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to erl_interface from 3.7.16 before 5.8.1, 5.7.0.1 and 5.5.2.1.
CVSS v4.0
Score 6.9medium
Affected software
pkg:github/erlang/otpcpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-49760 is a stack-based buffer overflow in the Erlang OTP erl_interface component, specifically in the ei_s_print_term function within lib/erl_interface/src/misc/ei_printterm.c. This function uses a fixed-size 2000-character stack buffer to format Erlang terms. When processing an encoded Erlang term containing a very large integer with an encoded representation exceeding 2000 characters, the buffer overflows. The overflowed bytes are limited to ASCII digits and uppercase hexadecimal letters, which constrains the exploitability to denial of service rather than arbitrary code execution. The companion function ei_print_term, which outputs directly to a FILE stream, does not exhibit this vulnerability. Affected versions include OTP releases from 17.0 before 29.0.2, 28.5.0.2, and 27.3.4.13, and erl_interface versions from 3.7.16 before 5.8.1, 5.7.0.1, and 5.5.2.1. No official patch or remediation level is provided in the available data.
Potential Impact
The buffer overflow can cause a denial of service condition due to stack corruption when processing specially crafted large integer terms. Exploitation is limited to denial of service because the overflowed data is restricted to ASCII characters 0-9 and A-F, preventing arbitrary code execution or other more severe impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided, users should monitor Erlang OTP vendor advisories for updates. Avoid using the vulnerable function ei_s_print_term with untrusted or excessively large encoded terms as a temporary mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-06-01T13:45:22.449Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a298ad7c9170919df367457
Added to database: 06/10/2026, 16:03:35 UTC
Last enriched: 07/24/2026, 21:36:34 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 122
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.