This update for erlang26 fixes the following issues:
public_key application accepts non-CA certificates as intermediate issuers and this enables chain
forgery (bsc#1266449).Subject CommonName fallback in TLS hostname verification allows for certificate
forgery by MITM attacker (bsc#1266466).epmd DoS via connection slot exhaustion due to improper handling of exceptional
conditions (bsc#1272908).zip:unzip/zip:extract via check_dir_level depth-counter bypass
(bsc#1272909).READLINK response leaks absolute backend filesystem path when root is configured (bsc#1268139).httpc leaks Authorization headers to cross-origin redirect targets (bsc#1268141).PASV response IP
address (bsc#1268142).ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN
allowlist (bsc#1268146).inet_drv (bsc#1268163).ei_s_print_term at very large integer (bsc#1268164).REALPATH path-existence oracle allows filesystem enumeration outside configured root
(bsc#1270245).LARGE_TUPLE_EXTP decoding in erts
external term format decoder (bsc#1272910).ClientHello
with mismatched PSK identity and binder list lengths (bsc#1270258).megaco flex scanner buffer overflow via oversized property parm name (bsc#1272914).