Erlang Ecosystem Foundation
CVE Numbering Authority for the BEAM ecosystem
A collaborative effort to assign and maintain CVE identifiers within the Erlang, Elixir, and Gleam ecosystem — a consistent, transparent process for reporting, documenting, and mitigating security vulnerabilities.
As a CNA (CVE Numbering Authority), we assign CVE IDs for vulnerabilities in active packages hosted on Hex.pm and in projects under the GitHub organizations listed in our scope. All CVEs are also published to OSV.dev. This CNA is hosted by the Erlang Ecosystem Foundation's Security Working Group.
Activity
CVE publications by quarter
Latest
Recently published
AshLua eval read operations can read field-policy-protected fields via aggregates
AshAi aggregate tool can read field-policy-protected fields
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
Resources
Learn more
CNA Scope
What projects we cover
Contact
Report a vulnerability
CVE Criteria
Assignment guidelines
Security Policy
Disclosure process
Common Weaknesses
CWE distribution
Maintainer Process
Coordinated disclosure guide
Coordinator Process
For CNA volunteers
Data Licensing
CC-BY 4.0 terms
All CVEs
Browse published records