Erlang Ecosystem Foundation
CVE Numbering Authority for the BEAM ecosystem
A collaborative effort to assign and maintain CVE identifiers within the Erlang, Elixir, and Gleam ecosystem — a consistent, transparent process for reporting, documenting, and mitigating security vulnerabilities.
As a CNA (CVE Numbering Authority), we assign CVE IDs for vulnerabilities in active packages hosted on Hex.pm and in projects under the GitHub organizations listed in our scope. All CVEs are also published to OSV.dev. This CNA is hosted by the Erlang Ecosystem Foundation's Security Working Group.
Activity
CVE publications by quarter
Latest
Recently published
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches
Resources
Learn more
CNA Scope
What projects we cover
Contact
Report a vulnerability
CVE Criteria
Assignment guidelines
Security Policy
Disclosure process
Common Weaknesses
CWE distribution
Maintainer Process
Coordinated disclosure guide
Coordinator Process
For CNA volunteers
Data Licensing
CC-BY 4.0 terms
All CVEs
Browse published records