critical severityConfidence highHistorical record

Erlang TLS 1.3 client can trust a server with no certificate

CVE-2026-89422 is a Critical (CVSS 4.0 9.3) TLS 1.3 client authentication bypass in Erlang/OTP ssl: an unsolicited ServerHello pre_shared_key extension causes ssl:connect to return {ok, Socket} without validating the peer certificate. Same-day siblings CVE-2026-68956 (SSH idle session-channel memory DoS) and CVE-2026-65634 (ASN.1 OID decode CPU DoS during TLS cert parse) share the OTP 29.1.1 / 28.5.0.7 / 27.3.4.18 patch train.

Also tracked as CVE-2026-89422 · CVE-2026-68956 · CVE-2026-65634 · GHSA-rgxr-4g4w-j875 · OTP TLS unsolicited PSK

First observed
Sep 22, 2026
Last observed
Sep 22, 2026
Last reviewed
Sep 22, 2026
Tracking ended
Sep 22, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

Confirm the exact OTP/ssl/ssh/asn1 patch level for your packaged release (Elixir, RabbitMQ, etc.) against the live ERLEF/GHSA sources. TLS 1.2-only clients are out of scope for 89422.

  • TLS clients restricted to TLS 1.2 are not affected by CVE-2026-89422.
  • CVE-2026-68956 requires an authenticated SSH session; max_channels is not a workaround.
  • CVE-2026-65634 is CPU DoS during OID/cert parse, not certificate forgery.
  • No configuration both keeps TLS 1.3 and mitigates CVE-2026-89422.
  • Does not invent CVSS or fixed versions beyond ERLEF/GHSA citations.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

No Guard coverage mapping is published for this record.

No campaign-specific policy guidance is published.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    ERLEF/OTP disclosed CVE-2026-89422 Critical TLS 1.3 client auth bypass plus siblings CVE-2026-68956 and CVE-2026-65634.

  2. Vendor action

    Patched OTP releases published: 29.1.1, 28.5.0.7, 27.3.4.18.

  3. Update

    HOL Guard published operator blog coverage for the OTP TLS cluster.

Publication clock: 13.2 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • erlang/otp@>=22.2 <27.3.4.18 || >=28.0 <28.5.0.7 || >=29.0 <29.1.1erlangpackage
  • ssl@>=9.5 <11.2.12.13 || >=11.3 <11.6.0.6 || >=11.7 <11.7.7erlangpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Security Publishing.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-0CAC6ABE