Erlang/OTP version lifecycle
runtime · Ericsson / OTP team
Current status
Supported version lines, end-of-life status, and latest releases for Erlang/OTP — derived from official vendor sources, not third-party EOL aggregators.
Erlang/OTP is a runtime and set of libraries for building scalable, fault-tolerant distributed systems.
Erlang/OTP security support covers the last three OTP major releases per SECURITY.md. CompatHub does not invent calendar EOL dates; a major leaves the window when a fourth newer major GA ships.
Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
9
Supported
3
EOL lines
6
Latest stable
29.0.6
2026-09-01
Releases tracked
144
At a glance
Latest release
29.0.6
Line 29
Recommended support line
29
standard support
Status
STANDARD SUPPORT
Newest supported: 29
EOL
Not published
Exact date not officially published
EOL lines include 26, 25, 24, 23, 22 (+1 more).
Recommended line: 29 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
3 currently supported release lines.
End-of-life versions
Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 29standard supportstandard support
- 28standard supportstandard support
- 27standard supportstandard support
- 26end of life · EOL 2026-05-27standard supportend of life
- 25end of life · EOL 2025-06-16standard supportend of life
- 24end of life · EOL 2024-07-10standard supportend of life
- 23end of life · EOL 2023-06-08standard supportend of life
- 22end of life · EOL 2022-06-09standard supportend of life
- 21end of life · EOL 2021-05-20standard supportend of life
Known exploited vulnerabilities
CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.
- CVE-2025-32433Known exploited
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
- CISA KEV:
- listed · added 2025-06-09 · due 2025-06-30
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- CVSS:
- 10.0 (critical) · NVD
- CWE:
- CWE-306
- Affected:
- >=27.0,<27.3.3
- Fixed in:
- 27.3.3
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- Known vulnerabilities
- 12
- Known exploited
- 1
- Highest CVSS
- 10.0
- CVE-2025-32433Known exploited
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
- CISA KEV:
- listed · added 2025-06-09 · due 2025-06-30
- Required action:
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- CVSS:
- 10.0 (critical) · NVD
- CWE:
- CWE-306
- Affected:
- >=27.0,<27.3.3
- Fixed in:
- 27.3.3
- CVE-2026-69664EEF-CVE-2026-69664
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
- CVSS:
- 8.7 (high) · NVD
- CWE:
- CWE-772
- Affected:
- >=77acb473d8f056f6f534395f131c6e45693797f0,<bd4e74348c6be8a49f060da6fd48d43f3a960292
- Fixed in:
- bd4e74348c6be8a49f060da6fd48d43f3a960292
- Source:
- OSV source · Advisory
- CVE-2026-74835EEF-CVE-2026-74835
inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
- CVSS:
- 8.7 (high) · NVD
- CWE:
- CWE-770
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<7f9c460d1818c2afb78fbd01f8d8b81343bbb011
- Fixed in:
- 7f9c460d1818c2afb78fbd01f8d8b81343bbb011
- Source:
- OSV source · Advisory
- CVE-2026-71380EEF-CVE-2026-71380
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
- CVSS:
- 8.7 (high) · NVD
- CWE:
- CWE-772
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<81b453aac5a006bb8d26405f2bc3cf24e9d7733c
- Fixed in:
- 81b453aac5a006bb8d26405f2bc3cf24e9d7733c
- Source:
- OSV source · Advisory
- CVE-2026-70399EEF-CVE-2026-70399
httpd does not enforce the documented default max_clients connection limit
- CVSS:
- 8.7 (high) · NVD
- CWE:
- CWE-770
- Affected:
- >=d9674f32811cd5bb02b0d6656053b5ee226bc74c,<e0050fc00c500a4fa9ba1f594603c787ff6d20b2
- Fixed in:
- e0050fc00c500a4fa9ba1f594603c787ff6d20b2
- Source:
- OSV source · Advisory
- CVE-2026-73812EEF-CVE-2026-73812
inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
- CVSS:
- 8.3 (high) · NVD
- CWE:
- CWE-444
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<591dc00dc99dc2a426167a3b5257c0c94bd45e91
- Fixed in:
- 591dc00dc99dc2a426167a3b5257c0c94bd45e91
- Source:
- OSV source · Advisory
- CVE-2026-73276EEF-CVE-2026-73276
inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
- CVSS:
- 8.3 (high) · NVD
- CWE:
- CWE-444
- Affected:
- >=c06db0bedf49a9b40725745e73fa82e562612815,<c285240c6e4b93960c5dc4f17ba04e6fdfb27a0f
- Fixed in:
- c285240c6e4b93960c5dc4f17ba04e6fdfb27a0f
- Source:
- OSV source · Advisory
- CVE-2026-66357EEF-CVE-2026-66357
inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
- CVSS:
- 8.3 (high) · NVD
- CWE:
- CWE-444
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<e640d599287d2eba919e6f13b91f042d7dbe6ff4
- Fixed in:
- e640d599287d2eba919e6f13b91f042d7dbe6ff4
- Source:
- OSV source · Advisory
- CVE-2026-66835EEF-CVE-2026-66835
httpd mod_auth directory protection bypassed by a doubled slash in the request path
- CVSS:
- 8.2 (high) · NVD
- CWE:
- CWE-50
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<9641944a2efbf55bea760f8ff7ba777fe3a0961c
- Fixed in:
- 9641944a2efbf55bea760f8ff7ba777fe3a0961c
- Source:
- OSV source · Advisory
- CVE-2026-73270EEF-CVE-2026-73270
httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
- CVSS:
- 8.2 (high) · NVD
- CWE:
- CWE-178
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<9641944a2efbf55bea760f8ff7ba777fe3a0961c
- Fixed in:
- 9641944a2efbf55bea760f8ff7ba777fe3a0961c
- Source:
- OSV source · Advisory
- CVE-2026-75538EEF-CVE-2026-75538
A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
- CVSS:
- 8.2 (high) · NVD
- CWE:
- CWE-122, CWE-190
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<08e8efdba8500d2d6f54c6b1de1492b228017c9b
- Fixed in:
- 08e8efdba8500d2d6f54c6b1de1492b228017c9b
- Source:
- OSV source · Advisory
- CVE-2026-55951EEF-CVE-2026-55951
httpc memory exhaustion via unbounded response header accumulation
- CVSS:
- 8.2 (high) · NVD
- CWE:
- CWE-770
- Affected:
- >=84adefa331c4159d432d22840663c38f155cd4c1,<e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa
- Fixed in:
- e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2026-09-01 · 3 in last 30 days · 6 in last 90 days
- 2026-09-01
- 2026-09-01
- 2026-08-04
- 2026-07-27
- 2026-07-02
- 2026-06-10
- 2026-05-27
- 2026-04-21
- 2026-04-07
- 2026-03-12
Should I upgrade?
Current versions are supported
The preferred supported release line is Erlang/OTP 29 (standard support).
Upgrade planning
Plan upgrades from Erlang/OTP version lines that have newer supported options.
Data coverage
Erlang/OTP security support covers the last three OTP major releases per SECURITY.md. CompatHub does not invent calendar EOL dates; a major leaves the window when a fourth newer major GA ships.
- Version lines
- 9
- Concrete releases
- 144
- Supported lines
- 3
- EOL lines
- 6
- Lifecycle coverage
- 9/9
- EOL coverage
- 6/6
- Provenance coverage
- 9/9
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-09-02
- Latest source update
- 2026-09-02
Sources
First-party and other registered sources contributing release and lifecycle facts.
- Erlang/OTP Security Policyfirst party · high
Official source: https://github.com/erlang/otp/blob/master/SECURITY.md
Last verified 2026-09-02
- RabbitMQ Erlang Compatibilityfirst party
Official source: https://raw.githubusercontent.com/rabbitmq/rabbitmq-website/main/docs/which-erlang.md
Last checked 2026-09-02
- Erlang/OTP GitHub Releasesfirst party
Official source: https://github.com/erlang/otp/releases
Last checked 2026-09-02
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-09-02
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-09-02
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-09-02
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
End of life
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 26 | end of lifehigh | 26.2.5 | 2025-02-20 | 2026-05-27 |
| 25 | end of lifehigh | 25.3.2 | 2024-02-08 | 2025-06-16 |
| 24 | end of lifehigh | 24.3.4 | 2023-02-23 | 2024-07-10 |
| 23 | end of lifehigh | 23.3.4 | 2021-11-11 | 2023-06-08 |
| 22 | end of lifehigh | 22.3.4 | 2020-09-25 | 2022-06-09 |
| 21 | end of lifehigh | 21.3.8 | 2020-09-25 | 2021-05-20 |
