CVE-2025-30211
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-30211: A memory consumption vulnerability affects Erlang/OTP, a collection of libraries used in the Erlang programming language, prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19. Maliciously formed KEX init messages can trigger high memory usage due to insufficient checks on algorithm names. These long names may lead to inefficient processing of error data, causing excessive memory allocation. The issue is resolved in OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19. Partial mitigations include setting `parallel_login` to `false` and reducing the `max_sessions` option.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Erlang