s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-89422

📛 CVE Title

TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension

Description

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTP 22.2 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.

Overview

State
PUBLISHED
Assigner (CNA)
EEF
CVSS severity
CRITICAL
CVSS score
CVSS 9.3 / 10 9.3 9.3 / 10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Effective score
9.3 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-322
Reserved
2026-09-11
Published
2026-09-22 08:49 UTC
Last updated
2026-09-22 13:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89422.json
Linked Threat
CVE-2026-89422 — TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-22 09:17:05 UTC
NVD last modified
2026-09-22 19:09:32 UTC
EPSS score
0.0037 (probability of exploitation in next 30 days)
EPSS percentile
30.70% vs all CVEs — higher = more likely to be exploited, as of 2026-09-22

NVD / KEV / EPSS data refreshed 2026-09-23 02:34 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-84338
Assigner
EEF
Published
Sep 22, 2026, 8:49:16 AM
Updated
Sep 22, 2026, 1:08:15 PM
EUVD base score (CVSS 4.0)
9.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EUVD-reported EPSS
0.3700
Vendors
erlang
Products
otp (9.5 <*)
otp (21b8a1b0ad0adf200682b3854bc50114ab2b8c62 <*)
otp (22.2 <*)

ENISA description: Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not. This issue affects OTP from OTP 22.2 before OTP 27.3.4.18, OTP 28.5.0.7, and OTP 29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.

EUVD references (8)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-09-26 03:08 UTC (source: CVRF).

MS severity
Critical
Release
2026-Sep
Microsoft remediations / KB articles (2)

Affected products (3)

VendorProductVersionsPlatforms
Erlang OTP 22.2 (affected) —
Erlang OTP 9.5 (affected) —
Erlang OTP 21b8a1b0ad0adf200682b3854bc50114ab2b8c62 (affected) —

Vendor references (8)

References embedded in the original CVE record by the assigning CNA.

Web references (2)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (8)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:blog.checkpoint.com

    CVE - 2026 -93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory. Fixes are available for both vulnerabilities. Customers running affected versions should install the applicable fixes immediately. Affected versions and remediation instructions are detailed below.

    2026-09-23 15:14 UTC
  • web:blog.qualys.com

    What can I do before Microsoft releases a patch ? Qualys TruRisk™ Eliminate provides a recommended mitigation for CVE - 2026 -69414 that can be applied to affected systems while Microsoft works on a fix . Assets can then be reassessed in Qualys VMDR to verify the remediation outcome.

    2026-09-23 15:14 UTC
  • web:cvebrief.com

    EEF CNA record for CVE-2026-89422 Related OSV record EEF- CVE - 2026 - 89422 Related Erlang/OTP version ordering Introducing commit 21b8a1b in erlang/otp Related Fix commit afec515 in erlang/otp Patch commit Fix commit 98c66c8 in erlang/otp Patch commit Fix commit fd1d9d0 in erlang/otp Patch commit External references: NVD entry · CVE .org

    2026-09-23 15:14 UTC
  • web:sec.cloudapps.cisco.com

    On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...

    2026-09-23 15:14 UTC
  • web:senserva.com

    Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.

    2026-09-23 15:14 UTC
  • web:support.sap.com

    SAP security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 9th of June 2026 , SAP security patch day saw the release of 15 new security notes.

    2026-09-23 15:14 UTC
  • web:support.servicenow.com

    Due to additional analysis provided by the security researcher who discovered CVE - 2026 -6876, we have upgraded the severity rating of CVE - 2026 -6876 from High to Critical. This change affects only the severity

    2026-09-23 15:14 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-09-23 15:14 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-09-23 15:14 UTC
  • web:www.techtimes.com

    July 2026 Patch Tuesday permanently removes the Kerberos RC4 rollback registry key on July 14, leaving service accounts with RC4-only material unable to authenticate. Administrators must also ...

    2026-09-23 15:14 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-89422.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-89422",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T13:08:04.474621Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T13:08:15.912Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "tls_client_connection_1_3",
            "tls_gen_connection_1_3",
            "tls_handshake_1_3"
          ],
          "packageName": "otp",
          "packageURL": "pkg:software-id/erlang.org/otp",
          "product": "OTP",
          "programFiles": [
            "lib/ssl/src/tls_client_connection_1_3.erl",
            "lib/ssl/src/tls_gen_connection_1_3.erl",
            "lib/ssl/src/tls_handshake_1_3.erl"
          ],
          "programRoutines": [
            {
              "name": "tls_client_connection_1_3:handle_server_hello/2"
            },
            {
              "name": "tls_client_connection_1_3:handle_encrypted_extensions/2"
            },
            {
              "name": "tls_client_connection_1_3:maybe_resumption/1"
            },
            {
              "name": "tls_gen_connection_1_3:handle_resumption/2"
            },
            {
              "name": "tls_handshake_1_3:get_pre_shared_key/4"
            }
          ],
          "vendor": "Erlang",
          "versions": [
            {
              "changes": [
                {
                  "at": "27.3.4.18",
                  "status": "unaffected"
                },
                {
                  "at": "28.5.0.7",
                  "status": "unaffected"
                },
                {
                  "at": "29.1.1",
                  "status": "unaffected"
                }
              ],
              "lessThan": "*",
              "status": "affected",
              "version": "22.2",
              "versionType": "otp"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "tls_client_connection_1_3",
            "tls_gen_connection_1_3",
            "tls_handshake_1_3"
          ],
          "packageName": "ssl",
          "packageURL": "pkg:otp/ssl?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
          "product": "OTP",
          "programFiles": [
            "src/tls_client_connection_1_3.erl",
            "src/tls_gen_connection_1_3.erl",
            "src/tls_handshake_1_3.erl"
          ],
          "programRoutines": [
            {
              "name": "tls_client_connection_1_3:handle_server_hello/2"
            },
            {
              "name": "tls_client_connection_1_3:handle_encrypted_extensions/2"
            },
            {
              "name": "tls_client_connection_1_3:maybe_resumption/1"
            },
            {
              "name": "tls_gen_connection_1_3:handle_resumption/2"
            },
            {
              "name": "tls_handshake_1_3:get_pre_shared_key/4"
            }
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "versions": [
            {
              "changes": [
                {
                  "at": "11.2.12.13",
                  "status": "unaffected"
                },
                {
                  "at": "11.6.0.6",
                  "status": "unaffected"
                },
                {
                  "at": "11.7.7",
                  "status": "unaffected"
                }
              ],
              "lessThan": "*",
              "status": "affected",
              "version": "9.5",
              "versionType": "otp"
            }
          ]
        },
        {
          "collectionURL": "https://github.com",
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "modules": [
            "tls_client_connection_1_3",
            "tls_gen_connection_1_3",
            "tls_handshake_1_3"
          ],
          "packageName": "erlang/otp",
          "packageURL": "pkg:github/erlang/otp",
          "product": "OTP",
          "programFiles": [
            "lib/ssl/src/tls_client_connection_1_3.erl",
            "lib/ssl/src/tls_gen_connection_1_3.erl",
            "lib/ssl/src/tls_handshake_1_3.erl"
          ],
          "programRoutines": [
            {
              "name": "tls_client_connection_1_3:handle_server_hello/2"
            },
            {
              "name": "tls_client_connection_1_3:handle_encrypted_extensions/2"
            },
            {
              "name": "tls_client_connection_1_3:maybe_resumption/1"
            },
            {
              "name": "tls_gen_connection_1_3:handle_resumption/2"
            },
            {
              "name": "tls_handshake_1_3:get_pre_shared_key/4"
            }
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "versions": [
            {
              "changes": [
                {
                  "at": "afec5156361bb50d3607c7c1a453c19b9149b324",
                  "status": "unaffected"
                },
                {
                  "at": "98c66c858113949c4262d26cd7d426c4b09d2b35",
                  "status": "unaffected"
                },
                {
                  "at": "fd1d9d07fc92ec0d59f96dfb66182195882bb7dd",
                  "status": "unaffected"
                }
              ],
              "lessThan": "*",
              "status": "affected",
              "version": "21b8a1b0ad0adf200682b3854bc50114ab2b8c62",
              "versionType": "git"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "27.3.4.18",
                  "versionStartIncluding": "22.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "28.5.0.7",
                  "versionStartIncluding": "28.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "29.1.1",
                  "versionStartIncluding": "29.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ],
          "operator": "AND"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Milad Nasr / Anthropic"
        },
        {
          "lang": "en",
          "type": "finder",
          "value": "Luna Tong / Anthropic"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Ingela Andin"
        }
      ],
      "dateAssigned": "2026-09-16T10:27:13.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A <code>pre_shared_key</code> extension in the <code>ServerHello</code> that the client never offered causes the client to complete the handshake without validating the server's certificate, so <code>ssl:connect</code> returns <code>{ok, Socket}</code> against a peer holding no certificate, no private key and no prior session.</p>\n<p><code>tls_client_connection_1_3:handle_server_hello/2</code> passes the received extension to <code>tls_gen_connection_1_3:handle_resumption/2</code>, which sets <code>resumption = true</code> on its mere presence without checking that the client offered a PSK. <code>tls_handshake_1_3:get_pre_shared_key/4</code> meanwhile falls back to the all-zero \"no PSK\" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes <code>maybe_resumption/1</code> straight to <code>wait_finished</code>, skipping the certificate-handling states, so certificate path validation, <code>verify_fun</code>, hostname verification, <code>partial_chain</code>, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not.</p>\n<p>This issue affects OTP from OTP&nbsp;22.2 before OTP&nbsp;27.3.4.18, OTP&nbsp;28.5.0.7, and OTP&nbsp;29.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7.</p>"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A `pre_shared_key` extension in the `ServerHello` that the client never offered causes the client to complete the handshake without validating the server's certificate, so `ssl:connect` returns `{ok, Socket}` against a peer holding no certificate, no private key and no prior session.\n\n`tls_client_connection_1_3:handle_server_hello/2` passes the received extension to `tls_gen_connection_1_3:handle_resumption/2`, which sets `resumption = true` on its mere presence without checking that the client offered a PSK. `tls_handshake_1_3:get_pre_shared_key/4` meanwhile falls back to the all-zero \"no PSK\" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes `maybe_resumption/1` straight to `wait_finished`, skipping the certificate-handling states, so certificate path validation, `verify_fun`, hostname verification, `partial_chain`, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not.\n\nThis issue affects OTP from OTP\u00a022.2 before OTP\u00a027.3.4.18, OTP\u00a028.5.0.7, and OTP\u00a029.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7."
            }
          ],
          "value": "Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session.\n\ntls_client_connection_1_3:handle_server_hello/2 passes the received extension to tls_gen_connection_1_3:handle_resumption/2, which sets resumption = true on its mere presence without checking that the client offered a PSK. tls_handshake_1_3:get_pre_shared_key/4 meanwhile falls back to the all-zero \"no PSK\" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key suffices. The resumption flag then routes maybe_resumption/1 straight to wait_finished, skipping the certificate-handling states, so certificate path validation, verify_fun, hostname verification, partial_chain, CRL checking and OCSP stapling are all bypassed. The default client configuration is affected; clients restricted to TLS 1.2 are not.\n\nThis issue affects OTP from OTP\u00a022.2 before OTP\u00a027.3.4.18, OTP\u00a028.5.0.7, and OTP\u00a029.1.1, corresponding to ssl from 9.5 before 11.2.12.13, 11.6.0.6, and 11.7.7."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-94",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "<p>An attacker that answers a TLS 1.3 client connection, either as the host the client dials or as an on-path attacker, completes the handshake as the intended server and holds all traffic keys. It can read everything the application sends, including credentials, tokens and request bodies, and forge every response. Any consumer of <code>ssl:connect</code> that negotiates TLS 1.3 is affected, including <code>httpc</code> over HTTPS, database and messaging client libraries, and TLS distribution clients.</p>"
                },
                {
                  "base64": false,
                  "type": "text/markdown",
                  "value": "An attacker that answers a TLS 1.3 client connection, either as the host the client dials or as an on-path attacker, completes the handshake as the intended server and holds all traffic keys. It can read everything the application sends, including credentials, tokens and request bodies, and forge every response. Any consumer of `ssl:connect` that negotiates TLS 1.3 is affected, including `httpc` over HTTPS, database and messaging client libraries, and TLS distribution clients."
                }
              ],
              "value": "An attacker that answers a TLS 1.3 client connection, either as the host the client dials or as an on-path attacker, completes the handshake as the intended server and holds all traffic keys. It can read everything the application sends, including credentials, tokens and request bodies, and forge every response. Any consumer of ssl:connect that negotiates TLS 1.3 is affected, including httpc over HTTPS, database and messaging client libraries, and TLS distribution clients."
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-322",
              "description": "CWE-322 Key Exchange without Entity Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T08:49:16.171Z",
        "orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "shortName": "EEF"
      },
      "references": [
        {
          "name": "GitHub Advisory",
          "tags": [
            "related",
            "vendor-advisory"
          ],
          "url": "https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875"
        },
        {
          "name": "EEF CNA record for CVE-2026-89422",
          "tags": [
            "related"
          ],
          "url": "https://cna.erlef.org/cves/CVE-2026-89422.html"
        },
        {
          "name": "OSV record EEF-CVE-2026-89422",
          "tags": [
            "related"
          ],
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-89422"
        },
        {
          "name": "Erlang/OTP version ordering",
          "tags": [
            "x_version-scheme"
          ],
          "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
        },
        {
          "name": "Introducing commit 21b8a1b in erlang/otp",
          "tags": [
            "related"
          ],
          "url": "https://github.com/erlang/otp/commit/21b8a1b0ad0adf200682b3854bc50114ab2b8c62"
        },
        {
          "name": "Fix commit afec515 in erlang/otp",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/erlang/otp/commit/afec5156361bb50d3607c7c1a453c19b9149b324"
        },
        {
          "name": "Fix commit 98c66c8 in erlang/otp",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/erlang/otp/commit/98c66c858113949c4262d26cd7d426c4b09d2b35"
        },
        {
          "name": "Fix commit fd1d9d0 in erlang/otp",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/erlang/otp/commit/fd1d9d07fc92ec0d59f96dfb66182195882bb7dd"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>Restrict affected clients to TLS 1.2 by setting <code>{versions, ['tlsv1.2']}</code> in the client's <code>ssl</code> options. This avoids the vulnerable code path at the cost of losing TLS 1.3.</p>\n<p>No configuration both keeps TLS 1.3 and mitigates the issue.</p>"
            },
            {
              "base64": false,
              "type": "text/markdown",
              "value": "Restrict affected clients to TLS 1.2 by setting `{versions, ['tlsv1.2']}` in the client's `ssl` options. This avoids the vulnerable code path at the cost of losing TLS 1.3.\n\nNo configuration both keeps TLS 1.3 and mitigates the issue."
            }
          ],
          "value": "Restrict affected clients to TLS 1.2 by setting {versions, ['tlsv1.2']} in the client's ssl options. This avoids the vulnerable code path at the cost of losing TLS 1.3.\n\nNo configuration both keeps TLS 1.3 and mitigates the issue."
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "assignerShortName": "EEF",
    "cveId": "CVE-2026-89422",
    "datePublished": "2026-09-22T08:49:16.171Z",
    "dateReserved": "2026-09-11T18:45:01.480Z",
    "dateUpdated": "2026-09-22T13:08:15.912Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}