CVE-2026-89422
Received Received - Intake

Key Exchange Without Entity Authentication in Erlang/OTP ssl

Vulnerability report for CVE-2026-89422, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: EEF

Description

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTPΒ 22.2 before OTPΒ 27.3.4.18, OTPΒ 28.5.0.7, and OTPΒ 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
erlang otp to 27.3.4.18 (exc)
erlang otp 27.3.4.18
erlang otp 28.5.0.7
erlang otp 29.1.1
erlang ssl to 11.2.12.13 (exc)
erlang ssl 11.2.12.13
erlang ssl 11.6.0.6
erlang ssl 11.7.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-322 The product performs a key exchange with an actor without verifying the identity of that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Key Exchange without Entity Authentication vulnerability in Erlang/OTP's ssl library for TLS 1.3 clients. When a server sends an unsolicited pre_shared_key extension in ServerHello, the client skips server certificate validation and completes the handshake without proper authentication. This allows an attacker to impersonate any server, intercept traffic, and forge responses.

Detection Guidance

Check Erlang/OTP versions with 'erl -version' to see if affected versions (22.2 to 27.3.4.18, 28.5.0.7, 29.1.1) are running. Monitor logs for ssl:peercert/1 returning {error, no_peercert} despite verify_peer settings. Look for session resumption flags in connection information even when no PSK was offered.

Impact Analysis

An attacker could impersonate a legitimate server, decrypt all traffic between client and server, and forge responses. This affects any application using ssl:connect with TLS 1.3, including HTTP clients, databases, and messaging libraries. The only visible sign may be ssl:peercert/1 returning no_peercert despite verify_peer being enabled.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It undermines secure communication channels, potentially causing non-compliance with data protection regulations that mandate encryption and server authentication.

Mitigation Strategies

Upgrade Erlang/OTP to patched versions (27.3.4.18, 28.5.0.7, 29.1.1 or ssl >= 11.2.12.13, 11.6.0.6, 11.7.7). If immediate upgrade is not possible, restrict clients to TLS 1.2 by setting {versions, ['tlsv1.2']} in ssl options, though this disables TLS 1.3 support.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89422. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart