The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1000 CWE-1000 at MITRE

We're looking at the CWE hierarchy through the Research Concepts view.

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages CVE-2026-104635 2026-10-09
Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts CVE-2026-101028 2026-10-09
beam_mcp: JSON boolean and null tool arguments reach dispatch as strings CVE-2026-104634 2026-10-08
beam_mcp: nested tool argument constraints advertised but not enforced CVE-2026-88257 2026-10-08
Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds CVE-2026-94206 2026-10-06
Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping CVE-2026-95105 2026-10-06
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash CVE-2026-94201 2026-10-05
Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries CVE-2026-94194 2026-09-28
Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size CVE-2026-92103 2026-09-28
HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory CVE-2026-91043 2026-09-28
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS CVE-2026-92106 2026-09-25
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash CVE-2026-93477 2026-09-25
Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy CVE-2026-91187 2026-09-24
Refresh tokens accepted as private repository credentials at the CDN CVE-2026-86698 2026-09-22
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed CVE-2026-87119 2026-09-22
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free CVE-2026-89420 2026-09-22
Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder
Erlang
pkg:otp/asn1
CVE-2026-65634 2026-09-22
SSH daemon allocates unbounded idle session channels, bypassing max_channels
Erlang
pkg:otp/ssh
CVE-2026-68956 2026-09-22
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
Erlang
Erlang / ssl
CVE-2026-89422 2026-09-22
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections CVE-2026-82672 2026-09-19
Session id is not renewed on authentication in ash_authentication, allowing session fixation CVE-2026-86688 2026-09-17
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement CVE-2026-76949 2026-09-17
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover CVE-2026-91039 2026-09-17
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication CVE-2026-85500 2026-09-17
25 per page · 324 CVEs
Page of 13