Description
Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass.

On DTLS server startup, dtls_server_connection:initial_hello/3 initializes previous_cookie_secret to the empty binary (<<>>) instead of a random value. Because HMAC with an empty key is deterministic, anyone who observes the plaintext ClientHello can compute dtls_handshake:cookie(<<>>, IP, Port, Hello) and forge a valid DTLS cookie before the first rotation of the cookie secret. The DTLS cookie (RFC 6347 §4.2.1) is a denial-of-service mitigation that prevents spoofed source IPs from forcing the server to allocate state and perform expensive cryptographic operations; it is not an authentication mechanism. During the window from server startup until the first secret rotation (0 to 15 seconds), an attacker who can observe the plaintext ClientHello can bypass the source address verification, enabling DTLS handshake amplification with spoofed source addresses.

This vulnerability is associated with program file lib/ssl/src/dtls_server_connection.erl and program routine dtls_server_connection:initial_hello/3.

This issue affects OTP from OTP 20.0 before 29.0.3, 28.5.0.3 and 27.3.4.14 corresponding to ssl from 8.2 before 11.7.3, 11.6.0.3 and 11.2.12.10.
Published: 2026-07-02
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in Erlang/OTP implementation. It is a CWE-1394 weakness involving improper initialization of a cryptographic key. During server startup, the DTLS cookie secret is initialized as an empty binary instead of a randomly generated value. Because HMAC with an empty key is deterministic, an attacker who can observe the plaintext ClientHello can compute a valid DTLS cookie using the formula provided in the RFC. Since the cookie is intended solely as a denial‑of‑service mitigation and not as an authentication mechanism, its predictability during the first 0‑15 seconds allows a spoofed source address to be accepted. This results in the server allocating resources for handshake attempts from forged addresses, potentially exhausting CPU or memory. The flaw does not grant code execution, privilege escalation, or data disclosure, but it introduces a mechanism for amplifying traffic against the target.

Affected Systems

Erlang:OTP releases from version , 29.0.3 are affected, and the specific sub-releases 28.5.0.3 and 27.3.4.14 are also vulnerable. Corresponding ssl modules 8.2 prior to 11.7.3, 11.6.0.3 and 11.2.12.10 contain the flaw.

Risk and Exploitability

The CVSSifies the vulnerability as medium severity. The EPSS score of < 1 % indicates a very low probability that attackers will exploit this flaw in the near term. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no public exploits are known. to passively monitor a client’s ClientHello and act within the brief startup window before the server rotates its secret. Successful exploitation would lead to resource exhaustion or intermittent would not provide code execution or other higher‑level capabilities.

Generated by OpenCVE AI on July 21, 2026 at 11:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Erlang/OTP to release 29.0.3 or newer, which initializes the DTLS cookie secret with a random value.
  • Apply a matching ssl module version that uses a non‑empty random key, such as 11.7.3 or later.
  • If an immediate upgrade is not possible, restrict inbound DTLS traffic to trusted networks and enforce rate limits during the server startup window to reduce the amplification effect.

Generated by OpenCVE AI on July 21, 2026 at 11:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Erlang erlang/otp
Vendors & Products Erlang erlang/otp

Thu, 02 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Description Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass. On DTLS server startup, dtls_server_connection:initial_hello/3 initializes previous_cookie_secret to the empty binary (<<>>) instead of a random value. Because HMAC with an empty key is deterministic, anyone who observes the plaintext ClientHello can compute dtls_handshake:cookie(<<>>, IP, Port, Hello) and forge a valid DTLS cookie before the first rotation of the cookie secret. The DTLS cookie (RFC 6347 §4.2.1) is a denial-of-service mitigation that prevents spoofed source IPs from forcing the server to allocate state and perform expensive cryptographic operations; it is not an authentication mechanism. During the window from server startup until the first secret rotation (0 to 15 seconds), an attacker who can observe the plaintext ClientHello can bypass the source address verification, enabling DTLS handshake amplification with spoofed source addresses. This vulnerability is associated with program file lib/ssl/src/dtls_server_connection.erl and program routine dtls_server_connection:initial_hello/3. This issue affects OTP from OTP 20.0 before 29.0.3, 28.5.0.3 and 27.3.4.14 corresponding to ssl from 8.2 before 11.7.3, 11.6.0.3 and 11.2.12.10.
Title DTLS server cookie bypass during startup window due to empty initial cookie secret
First Time appeared Erlang
Erlang erlang\/otp
Weaknesses CWE-1394
CPEs cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Vendors & Products Erlang
Erlang erlang\/otp
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Erlang Erlang/otp Erlang\/otp
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-07-03T04:29:00.191Z

Reserved: 2026-06-16T10:47:13.915Z

Link: CVE-2026-54887

cve-icon Vulnrichment

Updated: 2026-07-02T17:28:40.366Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:15:05Z

Weaknesses
  • CWE-1394

    Use of Default Cryptographic Key