Vulnerability description

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal.

This vulnerability is associated with program files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.

This issue affects otp: from 17.0, from 07b8f441ca711f9812fad9e9115bab3c3aa92f79; otp: from 5.10 before 7.0; otp: from 1.0.

Affected

pkg:github/erlang/otp

Module Source File
tftp_file lib/tftp/src/tftp_file.erl
Status Type Version Changes / Fixed in
affected otp 17.0
affected git 07b8f441ca71

pkg:otp/inets

Module Source File
tftp_file src/tftp_file.erl
Status Type Version Changes / Fixed in
affected otp 5.10 < 7.0

pkg:otp/tftp

Module Source File
tftp_file src/tftp_file.erl
Status Type Version Changes / Fixed in
affected otp 1.0
  • unaffected at 1.1.1.1
  • unaffected at 1.2.2.1
  • unaffected at 1.2.4

References

Credits

  • Reporter: Luigino Camastra
  • Remediation reviewer: Jakub Witczak
  • Remediation developer: Raimo Niskanen

CVE record as JSON:  GET /cves/CVE-2026-21620.json
OSV record as JSON:  GET /osv/EEF-CVE-2026-21620.json