Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 74%

CVE-2026-42789: CWE-295 Improper Certificate Validation in Erlang OTP

0
High
Published: 05/27/2026 (05/27/2026, 12:23:06 UTC)
Source: GCVE Database
Vendor/Project: Erlang
Product: OTP

Description

Two security vulnerabilities were identified in the Erlang OTP public_key module used by Red Hat OpenStack Services on OpenShift 18.0. These include a certificate chain forgery vulnerability due to improper trust chain validation (CVE-2026-42789) and a certificate validation bypass that allows hostname spoofing (CVE-2026-42790). Red Hat has issued an important security update addressing these issues. The vulnerabilities relate to improper certificate validation which could undermine trust in secure communications. No CVSS score is provided, but the impact is rated as high by Red Hat. A security update is available and should be applied to affected systems. No known exploits in the wild have been reported at this time.

CVSS v4.0

Score 7.0high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N

Affected software

GitHub Actionsmore threats →ai
erlang/otp
pkg:github/erlang/otp
Affected versions
<29.0.1=28.5.0.1=27.3.4.12=26.2.5.21
GitHub Actionsmore threats →ai
erlang/public_key
pkg:github/erlang/public_key
Affected versions
<1.21.1=1.20.3.1=1.17.1.3=1.15.1.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 17:00:00 UTC

Technical Analysis

Red Hat OpenStack Services on OpenShift 18.0 includes Erlang OTP, which has two security vulnerabilities in its public_key module. CVE-2026-42789 involves certificate chain forgery caused by improper validation of the trust chain, allowing attackers to potentially forge certificate chains. CVE-2026-42790 involves a certificate validation bypass that enables hostname spoofing, undermining the authenticity of TLS connections. These vulnerabilities affect the cryptographic trust mechanisms in Erlang OTP. Red Hat has released a security advisory RHSA-2026:39809 with updated Erlang packages to fix these issues. The advisory rates the impact as Important (high severity). The update is available for Red Hat OpenStack Services on OpenShift 18.0 (Antelope).

Potential Impact

The vulnerabilities allow attackers to bypass proper certificate validation, potentially enabling certificate chain forgery and hostname spoofing. This could compromise the security of TLS communications relying on Erlang OTP's public_key module, leading to man-in-the-middle attacks or impersonation of trusted entities. The impact is rated as high by Red Hat, indicating significant risk to confidentiality and integrity of communications in affected environments.

Mitigation Recommendations

Red Hat has released an official security update for Erlang in Red Hat OpenStack Services on OpenShift 18.0 that addresses these vulnerabilities. Users should apply the update as described in Red Hat advisory RHSA-2026:39809 and the referenced article https://access.redhat.com/articles/11258. No other mitigation or workaround is specified. There are no known exploits in the wild at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:39809
Cve Count
2
Additional Cves
["CVE-2026-42790"]
Cvss Version
null
Is Cloud Service
true

Threat ID: 6a7f440cbf8831d5395fb80b

Added to database: 08/14/2026, 16:36:28 UTC

Last enriched: 08/14/2026, 17:00:00 UTC

Last updated: 08/15/2026, 00:41:12 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses