“By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials.”
Erlang/OTP’s SSH server let anyone run commands without logging in. It scores a 10 out of 10. Every release since OTP 17 is affected, and so is anything built on the library, including Elixir apps. Patch or turn the SSH server off.