← Back to the live CVE advisory feed

CVE-2026-65634: Product identification pending

Severity
8.2 (HIGH)
Affected versions
Before 5.3.4.3
Fixed version
5.3.4.3
Patch status
Patched
Published
2026-09-22T09:17:05.090
Modified
2026-09-22T11:17:24.857

Why it matters

This matters because the affected product may be exploitable without valid credentials. Internet-facing deployments should be reviewed first.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:dec_subidentifiers/3 in lib/asn1/src/asn1rtt_ber.erl and the equivalent PER helper asn1rtt_per_common:dec_subidentifiers/3 in lib/asn1/src/asn1rtt_per_common.erl accumulate a base-128 subidentifier into an unbounded integer using (Av bsl 7) + H per continuation byte. Each shift and addition on the growing accumulator is linear in the number of bits already accumulated, giving quadratic total work in the size of a single subidentifier. The JER helper asn1rtt_jer:json2oid/1 in lib/asn1/src/asn1rtt_jer.erl exhibits the same class of unbounded-integer parsing when decoding a dot-separated OID from JSON. A DER-encoded OBJECT IDENTIFIER with one very large arc (approximately 262 KB of continuation bytes) consumes roughly 13 seconds of CPU on typical hardware. The vulnerable decoder is generated into every ASN.1 module that contains an OBJECT IDENTIFIER, including OTP-PUB-KEY which is reached during X.509 certificate parsing via public_key:pkix_decode_cert/2. This decoder runs before any signature or trust chain verification, so any Erlang service that parses peer TLS certificates is exposed: the default for TLS clients (which always parse the server certificate) and for mutual-TLS servers (which parse client certificates). This vulnerability is associated with program files lib/asn1/src/asn1rtt_ber.erl, lib/asn1/src/asn1rtt_per_common.erl and lib/asn1/src/asn1rtt_jer.erl and program routines asn1rtt_ber:dec_subidentifiers/3, asn1rtt_per_common:dec_subidentifiers/3 and asn1rtt_jer:json2oid/1. This issue affects OTP from OTP 17.0 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to asn1 from 3.0 before 5.3.4.3, 5.4.3.1, and 5.5.2. Whether OTP before OTP 17.0, corresponding to asn1 before 3.0, is affected is unknown.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 22, 2026 12:00 PM UTC
312 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77521
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-79920
ajenti PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-94301
Apache MINA
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85751
Mailu PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-13355
Meta Box Frontend Submission
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-19658
Give Tributes
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-25254
Snapdragon
Reporter: PRODUCT-SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-93952
VeloCloud Orchestrator (VCO) On-Prem
Reporter: PSIRT
9.5
CRITICAL
VIEW RECORD
CVE-2026-94571
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-94572
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-58491
warpgate PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-94424
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94425
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94493
PDV5701
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-89422
OTP PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9.3
CRITICAL
VIEW RECORD
CVE-2026-93556
Tankuam Places
Reporter: CVE-COORDINATION
9.3
CRITICAL
VIEW RECORD
CVE-2026-61674
fluent-bit PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-86473
Apache Airflow PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-46649
joplin PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79916
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-88807
Product identification pending PATCH
Reporter: MEISSNER
8.9
HIGH
VIEW RECORD
CVE-2026-55563
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.9
HIGH
VIEW RECORD
CVE-2026-84285
Product identification pending
Reporter: 3DS.INFORMATION-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-53940
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-82412
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62371
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-63116
deepstream.io PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-84990
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62182
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55159
luci-app-adblock-fast PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55897
luci PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-88409
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-92438
Ninja Forms
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2025-1281
BM Content Builder
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-25255
Snapdragon
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-25264
Product identification pending
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-25265
Product identification pending
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-16651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65652
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65653
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65654
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-89139
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94381
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.7
HIGH
VIEW RECORD
CVE-2026-94411
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94412
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94496
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94497
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94501
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-61652
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-94622
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94623
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94624
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94626
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94627
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90882
Product identification pending
Reporter: EMO
8.7
HIGH
VIEW RECORD
CVE-2026-94383
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.6
HIGH
VIEW RECORD
CVE-2025-71421
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-94403
iGameCenter
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55071
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-49811
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.4
HIGH
VIEW RECORD
CVE-2026-94374
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94401
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94488
Product identification pending PATCH
Reporter: CVE
8.3
HIGH
VIEW RECORD
CVE-2026-55074
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-65634
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-95511
Product identification pending
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2026-61628
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-80110
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-94184
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-77560
tinyauth PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-83621
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62369
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-58269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-92235
WP Ultimate Review
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-92969
HUSKY – Products Filter for WooCommerce Professional
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-65980
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.9
HIGH
VIEW RECORD
CVE-2026-55567
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-17052
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49810
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-81469
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-76898
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-63330
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-55105
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-59814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-94117
HashBar – WordPress Notification Bar PATCH
Reporter: AUDIT
7.6
HIGH
VIEW RECORD
CVE-2026-91863
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91864
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91865
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91866
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88806
Product identification pending PATCH
Reporter: MEISSNER
7.5
HIGH
VIEW RECORD
CVE-2026-52741
gocd PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-61629
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-71543
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-94449
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-73512
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73513
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.