Erlang/OTP is a widely deployed runtime (used by RabbitMQ, CouchDB, telco backends). A TLS certificate parsing bug can remotely DoS many Erlang-based services.
CVE-2026-65634
ASN.1 OID parser DoS in Erlang/OTP during TLS certificate parsing.
Is CVE-2026-65634 being exploited?
Not confirmed. CVE-2026-65634 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked.
How severe is CVE-2026-65634?
CVE-2026-65634 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-65634?
Yes. A fix has been recorded for CVE-2026-65634. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-65634 affect?
CVE-2026-65634 affects Erlang/OTP before 27.3.4.18, 28.5.0.7, 29.1.1, asn1 library (asn1rtt_ber, asn1rtt_per_common, asn1rtt_jer), Erlang-based products (e.g., RabbitMQ, CouchDB, other TLS clients/servers). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-65634?
Upgrade OTP to fixed releases or apply vendor patches immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote unauthenticated denial-of-service via crafted OBJECT IDENTIFIER in TLS handshake causing CPU exhaustion and service outages.
Immediate action required
- affected>= 17.0 and < *
- affected>= 3.0 and < *
- affected>= 84adefa331c4159d432d22840663c38f155cd4c1 and < 0fe2c02fdc06fab1c63be9db1a7456993d20f838
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.