The Erlang/OTP project reports:
OTP 29.1.1, 28.5.0.7 and 27.3.4.18 fix the following
issues:
- CVE-2026-89422: TLS 1.3 client skips server
authentication on unsolicited PSK. A pre_shared_key
extension in the ServerHello that the client never offered
causes the client to complete the handshake without
validating the server's certificate.
- CVE-2026-68956: SSH session channel exhaustion. The
max_channels daemon option only limited channels with an
active handler, so an authenticated client could open
unlimited idle session channels and exhaust the memory of
the whole Erlang VM.
- CVE-2026-65634: Superlinear CPU denial-of-service in
the asn1 OID decoder via large base-128 arcs.