CVE-2026-28810P4LOWCVSS 3.7≥ 17.0, < 26.2.5.19·≥ 27.0, < 27.3.4.10+1 more2026-04-07
CVE-2026-28810 [LOW] CWE-340 CVE-2026-28810: Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning.
The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization. Response validation relies almost entirely on this ID,
nvd