Erlang Ecosystem Foundation
CVE Numbering Authority for the BEAM ecosystem
A collaborative effort to assign and maintain CVE identifiers within the Erlang, Elixir, and Gleam ecosystem — a consistent, transparent process for reporting, documenting, and mitigating security vulnerabilities.
As a CNA (CVE Numbering Authority), we assign CVE IDs for vulnerabilities in active packages hosted on Hex.pm and in projects under the GitHub organizations listed in our scope. All CVEs are also published to OSV.dev. This CNA is hosted by the Erlang Ecosystem Foundation's Security Working Group.
Activity
CVE publications by quarter
Latest
Recently published
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Resources
Learn more
CNA Scope
What projects we cover
Contact
Report a vulnerability
CVE Criteria
Assignment guidelines
Security Policy
Disclosure process
Common Weaknesses
CWE distribution
Maintainer Process
Coordinated disclosure guide
Coordinator Process
For CNA volunteers
Data Licensing
CC-BY 4.0 terms
All CVEs
Browse published records