#VU125778 Improper Certificate Validation in otp - CVE-2026-32144
Published: April 10, 2026
otp
erlang
Description
The vulnerability allows a remote attacker to bypass certificate-based authentication.
The vulnerability exists due to improper certificate validation in OCSP designated-responder authorization handling when validating OCSP responses. A remote attacker can provide a crafted OCSP response to bypass certificate-based authentication.
Exploitation requires control of, or a man-in-the-middle position over, the server being validated.