{"id":"MGASA-2026-0457","summary":"Updated erlang package fixes security vulnerabilities","details":"SSH SFTP server denial of service via extended channel data infinite\nloop. (CVE-2026-54886)\nPlaintext APPLICATION_DATA injected during TLS handshake delivered to\nclient application post-handshake in ssl. (CVE-2026-54891)\nPlug: quadratic-time decoding of nested query/body parameters enables\ndenial of service. (CVE-2026-54892)\nEmail-derived URL path injection in the Swoosh Microsoft Graph adapter.\n(CVE-2026-54893)\n","modified":"2026-09-27T03:15:03.975907637Z","published":"2026-09-27T03:12:30Z","upstream":["CVE-2026-54886","CVE-2026-54891","CVE-2026-54892","CVE-2026-54893","CVE-2026-55952","CVE-2026-55953"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0457.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35971"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z643GQLCV3X4YNAD2P52IFBKQQU7E7A5/"},{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-7wp4-pc27-2vj9"},{"type":"ADVISORY","url":"https://cna.erlef.org/cves/CVE-2026-54886.html"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/EEF-CVE-2026-54886"},{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-gf6r-99xw-6qg6"},{"type":"ADVISORY","url":"https://cna.erlef.org/cves/CVE-2026-54891.html"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/EEF-CVE-2026-54891"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/EEF-CVE-2026-55952"},{"type":"ADVISORY","url":"https://cna.erlef.org/cves/CVE-2026-55952.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/45JCTFOGPTE2S5BCCCJH6KKGFNKZIDVS/"},{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882"},{"type":"ADVISORY","url":"https://cna.erlef.org/cves/CVE-2026-55953.html"},{"type":"ADVISORY","url":"https://osv.dev/vulnerability/EEF-CVE-2026-55953"},{"type":"WEB","url":"https://github.com/erlang/otp/releases/tag/OTP-27.3.4.16"},{"type":"WEB","url":"https://github.com/erlang/otp/releases/tag/OTP-27.3.4.17"}],"affected":[{"package":{"name":"erlang","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/erlang?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"27.3.4.17-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0457.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}