CVE-2025-46712: Erlang/OTP SSH Has Strict KEX Violations
Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake hardening measures by allowing optional messages to be exchanged. This allows a Man-in-the-Middle attacker to inject these messages in a connection during the handshake. This issue has been patched in versions OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25).
Other sources
Erlang/OTP SSH Has Strict KEX Violations
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 25.3.2.21-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.5.12-1 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in OTP-27.3.4 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in OTP-26.2.5.12 - Upgrade
Upgrade
Erlang/OTPto a version that resolves this vulnerability.Fixed in OTP-25.3.2.21
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46712?
CVE-2025-46712 is considered to have a high severity due to its impact on the SSH KEX handshake process.
How do I fix CVE-2025-46712?
To fix CVE-2025-46712, update your Erlang/OTP to versions OTP-27.3.4, OTP-26.2.5.12, or OTP-25.3.2.21 or later.
What versions of Erlang/OTP are affected by CVE-2025-46712?
CVE-2025-46712 affects Erlang/OTP versions prior to OTP-27.3.4, OTP-26.2.5.12, and OTP-25.3.2.21.
What functionality is compromised by CVE-2025-46712?
CVE-2025-46712 compromises the enforcement of strict KEX handshake hardening measures in Erlang/OTP SSH.
Is there a workaround for CVE-2025-46712?
There is no publicly documented workaround for CVE-2025-46712; upgrading is the recommended course of action.