CVE-2026-70409: eldap does not bound the port component of a referral URL before integer conversion
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits.
eldap:parseport/2 passes the port substring straight to listtointeger/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parseldapurl/1, which eldap never calls itself: referral strings are returned to the caller unparsed.
This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.
Affected Software
Event History
Frequently Asked Questions
Are applications using eldap affected by default?
No. eldap returns referral strings to the caller and does not invoke eldap:parse_ldap_url/1 itself. Exposure requires application code to pass an LDAP server-supplied referral into that parser.
What does an attacker need to exploit this issue?
The attacker must control or compromise an LDAP server that can return a referral URL, and the client application must parse that server-supplied referral with eldap:parse_ldap_url/1. The referral port must be a syntactically valid, extremely long sequence of digits.
What can be done if updating is not immediately possible?
Do not parse untrusted referral URLs unless necessary, and enforce a length limit on the port component before passing a referral to eldap:parse_ldap_url/1. The integer conversion accepts arbitrarily large integers, so callers must bound this input.
Which releases need to be updated?
Affected releases are OTP 17.0 through before 27.3.4.17, OTP 28.0 through before 28.5.0.6, and OTP 29.0 through before 29.0.6. The corresponding fixed eldap releases are 1.2.14.2, 1.2.16.1, and 1.3.1, respectively.