CVE-2026-70409 PUBLISHED

eldap does not bound the port component of a referral URL before integer conversion

Assigner: EEF
Reserved: 09.08.2026 Published: 01.09.2026 Updated: 01.09.2026

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits.

eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed.

This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 17.0 to 27.3.4.17 (excl.)
  • affected from 28.0 to 28.5.0.6 (excl.)
  • affected from 29.0 to 29.0.6 (excl.)
Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 1.0.3 to 1.2.14.2 (excl.)
  • affected from 1.2.15 to 1.2.16.1 (excl.)
  • affected from 1.3 to 1.3.1 (excl.)
Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from d8dbf15de4fa1a08b9a05e7d8e08fdb025fe1dc3 to * (excl.)

Credits

  • Eric Meadows-Jönsson finder
  • Jonatan Männchen / EEF finder
  • Peter Ullrich finder
  • José Valim finder
  • Konrad Pietrzak / Ericsson remediation developer

References

Problem Types

  • CWE-1284 Improper Validation of Specified Quantity in Input CWE

Impacts

  • CAPEC-231 Oversized Serialized Data Payloads