Am I affected?
This record states its affected versions in a form that can't be compared automatically.
≥
3.0.1
and up
affected
→
5.3.3
not affected
→
5.2.11.3
not affected
→
5.1.4.12
not affected
every other version:
unknown
Description
Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding.
This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
Weaknesses & attack patterns
Weakness
CWE-400
·
Uncontrolled Resource Consumption
in catalog →
MITRE ↗
CWE-770
·
Allocation of Resources Without Limits or Throttling
in catalog →
MITRE ↗
Affected — Erlang / ssh Repository ↗
≥
3.0.1
and up
affected
→
5.3.3
not affected
→
5.2.11.3
not affected
→
5.1.4.12
not affected
every other version:
unknown
default status
unknown
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files
modules
ssh_sftp
source files
lib/ssh/src/ssh_sftpd.erl
Affected — GitHub / erlang/otp Repository ↗
≥
17.0
and up
affected
→
28.0.3
not affected
→
27.3.4.3
not affected
→
26.2.5.15
not affected
≥
07b8f44
and up
affected
→
7cd7abb
not affected
→
548f129
not affected
every other version:
unknown
default status
unknown
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files
modules
ssh_sftp
source files
lib/ssh/src/ssh_sftpd.erl
Workarounds
- set option parallel_login to false
- reduce max_sessions option
References
github.com/erlang/otp ·
GHSA-h7rg-6rjg-4cph ↗
vendor-advisory
osv.dev ·
EEF-CVE-2025-48040 ↗
related
Credits
Jakub Witczak
Remediation developer
Ingela Anderton Andin
Remediation reviewer
CVSS breakdown
MEDIUM 6.9
open in calculator →
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N