CVE-2026-42789 Details
Description
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_extensions/7 contains two flaws that together allow a certificate with basicConstraints cA:false and no keyUsage extension to be used as an intermediate issuer in a chain passed to public_key:pkix_path_validation/3: the cA:false clause recurses into the remaining extensions without rejecting the certificate when it is in issuer position, and the keyUsage check only fires when the extension is present, so a certificate lacking keyUsage entirely bypasses the keyCertSign enforcement. Any party holding an end-entity certificate with basicConstraints cA:false and no keyUsage extension, issued by any CA in the victim's trust store, can use that certificate's private key to sign forged leaf certificates for arbitrary identities. public_key:pkix_path_validation/3 accepts the resulting chain, and by extension every TLS or mTLS endpoint built on the OTP ssl application that relies on the default verifier is affected, including server identity verification on the client side and client certificate verification on mTLS servers. This issue affects OTP from OTP 17.0 before OTP 29.0.1, OTP 28.5.0.1, OTP 27.3.4.12 and OTP 26.2.5.21, corresponding to public_key from 0.22 before 1.21.1, 1.20.3.1, 1.17.1.3 and 1.15.1.7.
A vulnerability in the public_key module of Erlang OTP, specifically in versions 17.0 prior to 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1, has been identified. This vulnerability allows a non-CA certificate to be incorrectly accepted as an intermediate issuer, facilitating certificate chain forgery. The issue arises because the validation function does not properly enforce the requirements of the basicConstraints and keyUsage extensions, as outlined in RFC 5280. Consequently, an end-entity certificate with basicConstraints set to cA:false and no keyUsage extension can be used to sign forged leaf certificates for arbitrary identities. This forged chain will be accepted by the public_key:pkix_path_validation/3 function, affecting any TLS or mTLS endpoint that relies on the default verifier.
Users can update to Erlang OTP versions 26.2.5.21, 27.3.4.12, 28.5.0.1, or 29.0.1 to address this vulnerability. Additionally, the verify_fun option in the ssl or public_key application can be used to reject chains that do not comply with the basicConstraints requirements.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:39809 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:54757 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42789 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482093 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42789.json | redhat-SADP | |
| https://cna.erlef.org/cves/CVE-2026-42789.html | EEF | Third Party Advisory |
| https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db | EEF | Patch |
| https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd | EEF | Patch |
| https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq | EEF | Vendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-42789 | EEF | Third Party Advisory |
| https://www.erlang.org/doc/system/versions.html#order-of-versions | EEF | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | redhat-SADP |
| CWE-295 | Improper Certificate Validation | EEF |
| CWE-296 | Improper Following of a Certificate's Chain of Trust | EEF |
Affected Products
| Product | Versions |
|---|---|
| erlang erlang/otp | >= 17.0, < 26.2.5.21 >= 27.0, < 27.3.4.12 >= 28.0, < 28.5.0.1 >= 29.0, < 29.0.1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | redhat-SADP |
| Sep 18, 2026 | CVE Modified | EEF |
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Jul 24, 2026 | CVE Modified | EEF |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | EEF |