CVE-2020-25623: Erlang Erlang/otp

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

Affected products

  • Erlang Erlang/otp: from 22.3.0, before 22.3.4.6 (fixed in 22.3.4.6); from 23.0.0, before 23.1 (fixed in 23.1)

Published 2020-10-02. Last modified 2026-06-17.