CVE-2026-70405
Received
Received - Intake
Denial of Service in Erlang/OTP SNMP
Vulnerability report for CVE-2026-70405, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-01
Last updated on: 2026-09-01
Assigner: EEF
Description
Description
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large.
snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2 then accumulates the value across every declared byte with a recursive shift and bitwise or. Work grows superlinearly in the declared length because each operation acts on a progressively larger bignum. The size-limited variant dec_integer_notag/2 exists but is reached from only one call site, dec_snmp_version/1, which bounds the version field to ten bytes; the request identifier, error status and index, generic and specific trap fields, engine boots and time, and every varbind value decoded by dec_value/1 all use the unbounded form. The decode runs before the PDU is processed, so no valid request is required beyond what the deployment demands to accept the message at all.
This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP before OTPΒ 17.0, corresponding to snmp before 4.25.1, is affected is unknown.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| erlang | otp | From 17.0 (inc) to 27.3.4.17 (exc) |
| erlang | otp | From 28.0 (inc) to 28.5.0.6 (exc) |
| erlang | otp | From 29.0 (inc) to 29.0.6 (exc) |
| erlang | snmp | From 4.25.1 (inc) to 5.18.2.1 (exc) |
| erlang | snmp | From 5.19 (inc) to 5.20.2.2 (exc) |
| erlang | snmp | From 5.20.3 (inc) to 5.20.5 (exc) |
| erlang | otp | to 27.3.4.17 (exc) |
| erlang | otp | to 28.5.0.6 (exc) |
| erlang | otp | to 29.0.6 (exc) |
| erlang | snmp | to 5.18.2.1 (exc) |
| erlang | snmp | to 5.20.2.2 (exc) |
| erlang | snmp | to 5.20.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |