CVE-2026-89422 Details
Description
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTP 22.2 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.
A vulnerability in the Erlang/OTP ssl application allows a peer to impersonate a server during a TLS 1.3 client connection. This issue arises because the client fails to authenticate the server when an unsolicited pre_shared_key extension is received. The vulnerability is present in Erlang/OTP versions 22.2 prior to 27.3.4.18, as well as in 28.5.0.7 and 29.1.1. Under the default client configuration, the vulnerability can be exploited by a malicious server or an on-path attacker, leading to a complete bypass of server authentication.
Users can upgrade to Erlang/OTP versions 27.3.4.18, 28.5.0.7, or 29.1.1, where this vulnerability has been fixed. For those unable to upgrade, a temporary workaround is to restrict the client to use TLS 1.2, which is not affected by this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-89422.html | EEF | AdvisoryBundle |
| https://github.com/erlang/otp/commit/21b8a1b0ad0adf200682b3854bc50114ab2b8c62 | EEF | Source CodeVendor |
| https://github.com/erlang/otp/commit/98c66c858113949c4262d26cd7d426c4b09d2b35 | EEF | Source CodeVendor |
| https://github.com/erlang/otp/commit/afec5156361bb50d3607c7c1a453c19b9149b324 | EEF | Source CodeVendor |
| https://github.com/erlang/otp/commit/fd1d9d07fc92ec0d59f96dfb66182195882bb7dd | EEF | Source CodeVendor |
| https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875 | EEF | AdvisoryVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-89422 | EEF | AdvisoryBundle |
| https://www.erlang.org/doc/system/versions.html#order-of-versions | EEF | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-322 | Key Exchange without Entity Authentication | EEF |
Affected Products
| Product | Versions |
|---|---|
| Erlang OTP | >= 22.2, < 27.3.4.18 >= 28.5.0.7 >= 29.1.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | EEF |
Volerion