l3nz
You may have seen that a critical security vulnerability has been disclosed in the OTP SSH implementation that could permit an attacker to execute arbitrary code sans any authentication under certain conditions.
If your run an Erlang SSH server, you need to act immediately.
More information in Unauthenticated Remote Code Execution in Erlang/OTP SSH · Advisory · erlang/otp · GitHub
Trending in Discussions
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
New
I want to open this thread for you all to discuss and help those who really like Ash but are still hesitant to use it in a real project. ...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
I’m posting this in response to Jose’s recent tweet (Cr. link) :
People are sleeping on Elixir for a coding harness:
Hot-code swappi...
New
It would be helpful to have a list of companies worldwide that hire engineers without prior experience in Elixir. Often, it can be quite ...
New
Anyone running long-lived stateful processes on BEAM? We’re building an AI agent runtime and would love to compare notes.
We’re a small ...
New
I’ve just put together a small POC exploring PDF inspection from Elixir/Phoenix:
The idea is pretty simple: drag & drop a PDF in a...
New
Other Trending Topics
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Hi there! We created Gust: A task orchestrator inspired by Airflow.
For those who have never heard about Aiflow, it’s a Python-based wor...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve.
They are GUI (Emerge) and State management (S...
New
There are three potential reasons for members of this forum to have a look at https://vutuv.de
You are tired or annoyed of LinkedIn.
Yo...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixirconf-us
- #blog-post
- #ai
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming










Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
realcorvus
I’ve published a writeup on this - What the Critical Erlang SSH Vulnerability Means for Elixir Developers
The summary is if you’re using Phoenix, you are most likely not affected. If you are using Nerves with SSH in production, you may be vulnerable. The Nerves team is aware of this issue and they are actively working on a solution so people can easily update.
D4no0
I see only 3 OTP versions mentioned, does this mean that OTP-24 and older don’t suffer from this issue?
realcorvus
I believe they are vulnerable, the root cause of the bug is related to the SSH handshake in Erlang. OTP-24 and older seem to be out of support, so they don’t get security updates - Erlang | endoflife.date
LostKobrakai
https://github.com/erlang/otp/blob/master/SECURITY.md
dch
Perhaps a Mod can move this to
Elixir Newscategory, this is an extremely serious vulnerability, albeit only for those who:There is already proof-of-concept code.
Work-around
Fix
Affected versions
Patched versions
NB only supported OTP releases are 25+
kevinschweikert
See also CVE-2025-32433: Major vulnerability in OTP's SSH server
axelson
There’s a fix out for this now. If you have an outdated system then I’d heartily recommend upgrading!
ricksonoliveira
I read it and I have a live app on fly.io using Phoenix, but when I nmpa’ed my app it says port 22/tcp is open for ssh.
I guess I’m vulnerable even though I use Phoenix and Fly.io, right?
realcorvus
Most likely no, port 22 is used internally by Fly.io for
fly ssh console, so it’s highly unlikely you are running an Erlang SSH server on that port.For you to be vulnerable, you have to do all of these:
:sshas an extra application in yourmix.exsfile. (It is off by default)When you nmap a Fly.io hosted app it will show port 22 is open, but that’s for Fly.io official use, your application is not running the Erlang SSH server on that port. For example, run:
nc your_domain_here 22If it returns
SSH-2.0-Erlang/VERSIONthen you are vulnerable. Most likely it will return nothing (I just tested it), and you are not vulnerable.ricksonoliveira
So I guess I’m really not because
nc your_domain_here 22returned nothing.Thanks!