Erlang Ecosystem Foundation
CVE Numbering Authority for the BEAM ecosystem
A collaborative effort to assign and maintain CVE identifiers within the Erlang, Elixir, and Gleam ecosystem — a consistent, transparent process for reporting, documenting, and mitigating security vulnerabilities.
As a CNA (CVE Numbering Authority), we assign CVE IDs for vulnerabilities in active packages hosted on Hex.pm and in projects under the GitHub organizations listed in our scope. All CVEs are also published to OSV.dev. This CNA is hosted by the Erlang Ecosystem Foundation's Security Working Group.
Activity
CVE publications by quarter
Latest
Recently published
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
eldap does not bound the port component of a referral URL before integer conversion
snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
Resources
Learn more
CNA Scope
What projects we cover
Contact
Report a vulnerability
CVE Criteria
Assignment guidelines
Security Policy
Disclosure process
Common Weaknesses
CWE distribution
Maintainer Process
Coordinated disclosure guide
Coordinator Process
For CNA volunteers
Data Licensing
CC-BY 4.0 terms
All CVEs
Browse published records