Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of… (CVE-2026-65634)
A vulnerability in Erlang/OTP's ASN.1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause a denial of service by sending a specially crafted OID during the TLS handshake. The issue arises from inefficient algorithmic complexity in decoding large OBJECT IDENTIFIER subidentifiers, leading to excessive CPU consumption. This affects Erlang/OTP versions from 17.0 up to but not including 27.3.4.18, 28.5.0.7, and 29.1.1, corresponding to affected asn1 library versions. The vulnerability impacts any Erlang service parsing peer TLS certificates, including TLS clients and mutual-TLS servers. No known exploits are reported in the wild. Patch status is not explicitly confirmed in the provided data.
AI Analysis
Technical Summary
The Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder contains an inefficient algorithmic complexity flaw in the BER, PER, and JER decoding routines for OBJECT IDENTIFIER subidentifiers. Specifically, the decoder accumulates base-128 subidentifiers into an unbounded integer using a process with quadratic time complexity relative to the size of the subidentifier. This allows an attacker to craft a DER-encoded OBJECT IDENTIFIER with a very large arc (approximately 262 KB of continuation bytes), causing the decoder to consume excessive CPU time (about 13 seconds on typical hardware) during TLS handshake certificate parsing. The vulnerable code is present in OTP versions from 17.0 before 27.3.4.18, 28.5.0.7, and 29.1.1, affecting the asn1 library versions 3.0 before 5.3.4.3, 5.4.3.1, and 5.5.2. The vulnerability is exploitable remotely without authentication and affects services that parse peer TLS certificates before signature or trust chain verification.
Potential Impact
An attacker can remotely cause a denial of service by sending a crafted OBJECT IDENTIFIER during the TLS handshake, leading to excessive CPU consumption and service disruption. This affects Erlang services that parse TLS certificates, including default TLS clients and mutual-TLS servers. There is no indication of privilege escalation, data disclosure, or code execution. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, consider limiting the size of OBJECT IDENTIFIERs accepted during TLS handshake or applying rate limiting on TLS connections to mitigate potential denial of service. Monitor vendor channels for updates and apply patches promptly once available.
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of… (CVE-2026-65634)
Description
A vulnerability in Erlang/OTP's ASN.1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause a denial of service by sending a specially crafted OID during the TLS handshake. The issue arises from inefficient algorithmic complexity in decoding large OBJECT IDENTIFIER subidentifiers, leading to excessive CPU consumption. This affects Erlang/OTP versions from 17.0 up to but not including 27.3.4.18, 28.5.0.7, and 29.1.1, corresponding to affected asn1 library versions. The vulnerability impacts any Erlang service parsing peer TLS certificates, including TLS clients and mutual-TLS servers. No known exploits are reported in the wild. Patch status is not explicitly confirmed in the provided data.
CVSS v4.0
Affected software
pkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/erlang?arch=source&distro=jammypkg:deb/ubuntu/erlang?arch=source&distro=noblepkg:deb/ubuntu/erlang?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder contains an inefficient algorithmic complexity flaw in the BER, PER, and JER decoding routines for OBJECT IDENTIFIER subidentifiers. Specifically, the decoder accumulates base-128 subidentifiers into an unbounded integer using a process with quadratic time complexity relative to the size of the subidentifier. This allows an attacker to craft a DER-encoded OBJECT IDENTIFIER with a very large arc (approximately 262 KB of continuation bytes), causing the decoder to consume excessive CPU time (about 13 seconds on typical hardware) during TLS handshake certificate parsing. The vulnerable code is present in OTP versions from 17.0 before 27.3.4.18, 28.5.0.7, and 29.1.1, affecting the asn1 library versions 3.0 before 5.3.4.3, 5.4.3.1, and 5.5.2. The vulnerability is exploitable remotely without authentication and affects services that parse peer TLS certificates before signature or trust chain verification.
Potential Impact
An attacker can remotely cause a denial of service by sending a crafted OBJECT IDENTIFIER during the TLS handshake, leading to excessive CPU consumption and service disruption. This affects Erlang services that parse TLS certificates, including default TLS clients and mutual-TLS servers. There is no indication of privilege escalation, data disclosure, or code execution. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is confirmed, consider limiting the size of OBJECT IDENTIFIERs accepted during TLS handshake or applying rate limiting on TLS connections to mitigate potential denial of service. Monitor vendor channels for updates and apply patches promptly once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-65634
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab4be55f7a7c54106f0aa46
Added to database: 09/24/2026, 06:08:21 UTC
Last enriched: 09/24/2026, 06:47:47 UTC
Last updated: 09/24/2026, 22:47:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.