Critical severity9.8NVD Advisory· Published Sep 21, 2022· Updated Jun 17, 2026
CVE-2022-37026
CVE-2022-37026
Description
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
27- Erlang/OTP/Erlang/OTPdescription
- osv-coords24 versionspkg:rpm/opensuse/erlang&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/erlang&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/erlang&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/erlang&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/erlang27&distro=openSUSE%20Tumbleweedpkg:rpm/suse/erlang&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/erlang&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/erlang&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/erlang&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/erlang&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/erlang&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/erlang&distro=SUSE%20Manager%20Server%204.2
< 22.3-150300.3.3.1+ 23 more
- (no CPE)range: < 22.3-150300.3.3.1
- (no CPE)range: < 22.3-150300.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 25.1.1-1.1
- (no CPE)range: < 27.1.3-1.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.3-150300.3.3.1
- (no CPE)range: < 22.3-150300.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.2.7-150200.3.3.1
- (no CPE)range: < 22.3-150300.3.8.1
Patches
Vulnerability mechanics
References
4- github.com/erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15nvdPatchThird Party Advisory
- erlangforums.com/c/erlang-news-announcements/91nvdRelease NotesVendor Advisory
- erlangforums.com/t/otp-25-1-released/1854nvdRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2023/07/msg00012.htmlnvd
News mentions
0No linked articles in our index yet.