Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftpfile modules), erlang otp inets (tftpfile modules), erlang otp tftp (tftpfile modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftpfile.erl, src/tftp_file.erl.
This issue affects OTP from OTP 17.0 before OTP 28.3.2, OTP 27.3.4.8 and OTP 26.2.5.17, corresponding to tftp from 1.0 before 1.2.4, 1.2.2.1 and 1.1.1.1; also inets from 5.10 before 7.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21620.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "17.0"
},
{
"fixed": "*"
},
{
"introduced": "07b8f441ca711f9812fad9e9115bab3c3aa92f79"
},
{
"fixed": "*"
},
{
"introduced": "5.10"
},
{
"fixed": "7.0"
},
{
"introduced": "1.0"
},
{
"fixed": "*"
}
]
}
],
"cna_assigner": "EEF",
"cwe_ids": [
"CWE-23"
]
}{
"source": [
"CPE_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "26.2.5.17"
},
{
"introduced": "27.0"
},
{
"fixed": "27.3.4.8"
},
{
"introduced": "28.0"
},
{
"fixed": "28.3.2"
}
]
}