Erlang TLS 1.3 client can trust a server with no certificate
CVE-2026-89422 is a Critical (CVSS 4.0 9.3) TLS 1.3 client authentication bypass in Erlang/OTP ssl: an unsolicited ServerHello pre_shared_key extension causes ssl:connect to return {ok, Socket} without validating the peer certificate. Same-day siblings CVE-2026-68956 (SSH idle session-channel memory DoS) and CVE-2026-65634 (ASN.1 OID decode CPU DoS during TLS cert parse) share the OTP 29.1.1 / 28.5.0.7 / 27.3.4.18 patch train.
Also tracked as CVE-2026-89422 · CVE-2026-68956 · CVE-2026-65634 · GHSA-rgxr-4g4w-j875 · OTP TLS unsolicited PSK
- First observed
- Sep 22, 2026
- Last observed
- Sep 22, 2026
- Last reviewed
- Sep 22, 2026
- Tracking ended
- Sep 22, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Confirm the exact OTP/ssl/ssh/asn1 patch level for your packaged release (Elixir, RabbitMQ, etc.) against the live ERLEF/GHSA sources. TLS 1.2-only clients are out of scope for 89422.
- TLS clients restricted to TLS 1.2 are not affected by CVE-2026-89422.
- CVE-2026-68956 requires an authenticated SSH session; max_channels is not a workaround.
- CVE-2026-65634 is CPU DoS during OID/cert parse, not certificate forgery.
- No configuration both keeps TLS 1.3 and mitigates CVE-2026-89422.
- Does not invent CVSS or fixed versions beyond ERLEF/GHSA citations.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
No Guard coverage mapping is published for this record.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
ERLEF/OTP disclosed CVE-2026-89422 Critical TLS 1.3 client auth bypass plus siblings CVE-2026-68956 and CVE-2026-65634.
- Vendor action
Patched OTP releases published: 29.1.1, 28.5.0.7, 27.3.4.18.
- Update
HOL Guard published operator blog coverage for the OTP TLS cluster.
Publication clock: 13.2 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
erlang/otp@>=22.2 <27.3.4.18 || >=28.0 <28.5.0.7 || >=29.0 <29.1.1erlangpackagessl@>=9.5 <11.2.12.13 || >=11.3 <11.6.0.6 || >=11.7 <11.7.7erlangpackage
Sources
Every claim on this record is traceable to the sources below.
- ERLEF CNA CVE-2026-89422maintainer advisory · observed September 22, 2026
- GHSA-rgxr-4g4w-j875maintainer advisory · observed September 22, 2026
- ERLEF CNA CVE-2026-68956maintainer advisory · observed September 22, 2026
- ERLEF CNA CVE-2026-65634maintainer advisory · observed September 22, 2026
- OTP 29.1.1 releaseother primary · observed September 22, 2026
- HOL Guard operator write-upother primary · observed September 22, 2026
- HOL Guard evidence pack CVE-2026-89422other primary · observed September 22, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-0CAC6ABE