FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang/OTP -- OCSP responder certificate accepted after expiry in public_key

Affected packages
erlang-runtime27 < 27.3.4.12
erlang-runtime28 < 28.5.0.1
erlang-runtime29 < 29.0.1

Details

VuXML ID 9357d6fb-5a54-11f1-b886-4c526214c986
Discovery 2026-05-27
Entry 2026-05-28

https://github.com/erlang/otp/security/advisories/GHSA-cjxj-wj6x-3fff reports:

Erlang/OTP's public_key application fails to validate the validity period of OCSP responder certificates during response verification. An attacker possessing an expired OCSP responder's private key can forge responses that the system accepts as valid, potentially allowing acceptance of revoked TLS certificates in OCSP stapling scenarios or authentication bypass in applications using the public_key:pkix_ocsp_validate/5 API directly.

References

CVE Name CVE-2026-42791
URL https://github.com/erlang/otp/security/advisories/GHSA-cjxj-wj6x-3fff