cbcvebase.
CVE-2026-23943
published 2026-03-13

CVE-2026-23943: Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource…

PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.64%
48.5th percentile
Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS. Two compression algorithms are affected: * zlib: Activates immediately after key exchange, enabling unauthenticated attacks * [email protected]: Activates post-authentication, enabling authenticated attacks Each SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exhaust available memory, causing OOM kills in memory-constrained environments. This vulnerability is associated with program files lib/ssh/src/ssh_transport.erl and program routines ssh_transport:decompress/2, ssh_transport:handle_packet_part/4. This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianerlang< erlang 1:27.3.4.9+dfsg-1 (forky)erlang 1:27.3.4.9+dfsg-1 (forky)
erlangerlang_otp>= 17.0 < 26.2.5.1826.2.5.18
erlangerlang_otp>= 27.0 < 27.3.4.927.3.4.9
erlangerlang_otp>= 28.0 < 28.4.128.4.1
erlangerlang_ssh>= 3.0.1 < 5.1.4.145.1.4.14
erlangerlang_ssh>= 5.2 < 5.2.11.65.2.11.6
erlangerlang_ssh5.5 – 5.5.1
erlangotp>= 07b8f441ca711f9812fad9e9115bab3c3aa92f79 < **
erlangotp>= 17.0 < **
erlangotp>= 3.0.1 < **
msrcazl3_erlang_26.2.5.17-1_on_azure_linux_3.0
msrccbl2_erlang_25.3.2.21-4_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_msrc6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.