Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| https://github.com/erlang/otp | affected | < ae0052c7f891ce805e2b53493a5304e2ee008aeb | vendor fix → ae0052c7f891ce805e2b53493a5304e2ee008aeb | osv | |
| https://github.com/erlang/otp | affected | >= 8c0ea6bd3306cfd6ca19730d180a2a93a716e1ee, < 9f6c4eb54823324d1e6f8cb95c15feb09f09044e | vendor fix → 9f6c4eb54823324d1e6f8cb95c15feb09f09044e | osv | |
| https://github.com/erlang/otp | affected | >= 601a012837ea0a5c8095bf24223132824177124d, < 10e20b1dbe39b056fab430e50b08cb4f3696ae87 | vendor fix → 10e20b1dbe39b056fab430e50b08cb4f3696ae87 | osv | |
| https://github.com/erlang/otp | affected | < 0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 | vendor fix → 0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 | osv | |
| https://github.com/erlang/otp | affected | < 6eef04130afc8b0ccb63c9a0d8650209cf54892f | vendor fix → 6eef04130afc8b0ccb63c9a0d8650209cf54892f | osv | |
| https://github.com/erlang/otp | affected | < b1924d37fd83c070055beb115d5d6a6a9490b891 | vendor fix → b1924d37fd83c070055beb115d5d6a6a9490b891 | osv | |
| https://github.com/erlang/otp | fixed | ae0052c7f891ce805e2b53493a5304e2ee008aeb | vendor fix → ae0052c7f891ce805e2b53493a5304e2ee008aeb | osv | |
| https://github.com/erlang/otp | fixed | 9f6c4eb54823324d1e6f8cb95c15feb09f09044e | vendor fix → 9f6c4eb54823324d1e6f8cb95c15feb09f09044e | osv | |
| https://github.com/erlang/otp | fixed | 10e20b1dbe39b056fab430e50b08cb4f3696ae87 | vendor fix → 10e20b1dbe39b056fab430e50b08cb4f3696ae87 | osv | |
| https://github.com/erlang/otp | fixed | 0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 | vendor fix → 0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 | osv | |
| https://github.com/erlang/otp | fixed | 6eef04130afc8b0ccb63c9a0d8650209cf54892f | vendor fix → 6eef04130afc8b0ccb63c9a0d8650209cf54892f | osv | |
| https://github.com/erlang/otp | fixed | b1924d37fd83c070055beb115d5d6a6a9490b891 | vendor fix → b1924d37fd83c070055beb115d5d6a6a9490b891 | osv | |
| erlang/otp erlang · otp | affected | >= OTP-27.0-rc1, < OTP-27.3.3 | none available | cve_cna | |
| erlang/otp erlang · otp | affected | >= OTP-26.0-rc1, < OTP-26.2.5.11 | none available | cve_cna | |
| erlang/otp erlang · otp | affected | < OTP-25.3.2.20 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.