{"schema_version":"1.9.0","id":"CVE-2022-37026","published":"2022-09-21T00:00:00Z","modified":"2026-08-12T03:51:35.509712073Z","related":["SUSE-SU-2022:4215-1","SUSE-SU-2022:4222-1","SUSE-SU-2023:3401-1","SUSE-SU-2023:3409-1","SUSE-SU-2023:4109-1","openSUSE-SU-2024:12416-1","openSUSE-SU-2025:15740-1"],"details":"In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erlang/otp","events":[{"introduced":"0"},{"fixed":"8e9201679129a42c9a2a78940dae83a058be68f2"},{"introduced":"583cba31eb09c14abd0b217fe7ac2e9a60425d51"},{"fixed":"0251f542a2ef42ded2a146649d05ff9e7e457268"},{"introduced":"4ed7957623e5ccbd420a09a506bd6bc9930fe93c"},{"fixed":"ac0c9879c68b23278178a7afe738285b33ff1832"}],"database_specific":{"cpe":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"23.3.4.15"},{"introduced":"24.0"},{"fixed":"24.3.4.2"},{"introduced":"25.0"},{"fixed":"25.0.2"}],"source":"CPE_RANGE"}}],"versions":["OTP-25.0","patch-base-24","OTP-24.3.4","OTP-24.3","OTP-24.0","OTP-23.3.4","OTP-23.3","OTP-23.0","OTP-24.3.4.1","OTP-21.0","OTP-23.3.4.14","OTP-25.0.1","OTP-24.3.3","OTP-23.3.4.2","OTP-23.3.4.13","OTP-24.3.2","OTP-23.3.4.12","OTP-23.3.4.11","OTP-24.3.1","OTP-24.2","OTP-23.3.4.8","OTP-23.2","OTP-23.3.4.10","OTP-23.3.4.9","OTP-24.1","OTP-23.3.4.7","OTP-22.0","OTP-23.3.4.6","OTP-23.3.4.5","OTP-23.3.4.4","OTP-23.3.2","OTP-23.3.4.3","OTP-23.3.4.1","OTP-23.3.3","OTP-23.3.1","OTP-23.1","OTP-23.0-rc3","OTP-23.0-rc2","OTP-23.0-rc1","OTP-20.0","OTP-22.0-rc3","OTP-22.0-rc2","OTP-22.0-rc1","OTP-19.0","OTP-21.0-rc2","OTP-18.0","OTP-21.0-rc1","OTP-17.0","OTP-20.0-rc2","OTP-20.0-rc1","OTP-19.0-rc2","OTP-19.0-rc1","OTP_R16B","OTP-18.0-rc1","OTP_17.0-rc2","OTP_17.0-rc1","OTP_R13B03","OTP_R16A_RELEASE_CANDIDATE","OTP_R14B03","OTP_R15B","OTP_R15A","OTP_R14B02","OTP_R14B01","OTP_R14B","OTP_R13B04","OTP_R14A"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37026.json"}}],"references":[{"type":"WEB","url":"https://erlangforums.com/c/erlang-news-announcements/91"},{"type":"WEB","url":"https://erlangforums.com/t/otp-25-1-released/1854"},{"type":"WEB","url":"https://github.com/erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37026.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37026"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00012.html"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37026.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}