MGASA-2026-0457

Source
https://advisories.mageia.org/MGASA-2026-0457.html
Import Source
https://advisories.mageia.org/MGASA-2026-0457.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0457
Upstream
CVE (6)
Published
2026-09-27T03:12:30Z
Modified
2026-09-27T03:15:03Z
Summary
Updated erlang package fixes security vulnerabilities
Details

SSH SFTP server denial of service via extended channel data infinite loop. (CVE-2026-54886) Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl. (CVE-2026-54891) Plug: quadratic-time decoding of nested query/body parameters enables denial of service. (CVE-2026-54892) Email-derived URL path injection in the Swoosh Microsoft Graph adapter. (CVE-2026-54893)

References
Credits

Affected packages

Mageia:10 / erlang

Package

Name
erlang
Purl
pkg:rpm/mageia/erlang?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
27.3.4.17-1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0457.json"