{"type":"bundle","id":"bundle--b4c21900-d8c0-5108-b321-2fd3f583c795","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--4d46b7b8-274a-5984-8b4c-7eef855860c8","created":"2026-09-22T13:11:48.957Z","modified":"2026-09-22T13:11:48.957Z","name":"Erlang TLS 1.3 client can trust a server with no certificate","description":"CVE-2026-89422 is a Critical (CVSS 4.0 9.3) TLS 1.3 client authentication bypass in Erlang/OTP ssl: an unsolicited ServerHello pre_shared_key extension causes ssl:connect to return {ok, Socket} without validating the peer certificate. Same-day siblings CVE-2026-68956 (SSH idle session-channel memory DoS) and CVE-2026-65634 (ASN.1 OID decode CPU DoS during TLS cert parse) share the OTP 29.1.1 / 28.5.0.7 / 27.3.4.18 patch train.","aliases":["CVE-2026-89422","CVE-2026-68956","CVE-2026-65634","GHSA-rgxr-4g4w-j875","OTP TLS unsolicited PSK"],"first_seen":"2026-09-22T00:00:00.000Z","last_seen":"2026-09-22T13:05:20.971Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"ERLEF CNA CVE-2026-89422","url":"https://cna.erlef.org/cves/CVE-2026-89422.html"},{"source_name":"GHSA-rgxr-4g4w-j875","url":"https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875"},{"source_name":"ERLEF CNA CVE-2026-68956","url":"https://cna.erlef.org/cves/CVE-2026-68956.html"},{"source_name":"ERLEF CNA CVE-2026-65634","url":"https://cna.erlef.org/cves/CVE-2026-65634.html"},{"source_name":"OTP 29.1.1 release","url":"https://github.com/erlang/otp/releases/tag/OTP-29.1.1"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-89422-erlang-otp-tls13-unsolicited-psk-auth-bypass"},{"source_name":"HOL Guard evidence pack CVE-2026-89422","url":"https://hol.org/guard/security/cves/CVE-2026-89422"}]}]}