Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Viewing · CWE-1000
Switch view
CWE-1000 at MITRE
We're looking at the CWE hierarchy through the Research Concepts view.
CVEs
Every CVE in this view
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages | CVE-2026-104635 | 2026-10-09 | |
| Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts | CVE-2026-101028 | 2026-10-09 | |
| beam_mcp: JSON boolean and null tool arguments reach dispatch as strings | CVE-2026-104634 | 2026-10-08 | |
| beam_mcp: nested tool argument constraints advertised but not enforced | CVE-2026-88257 | 2026-10-08 | |
| Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds | CVE-2026-94206 | 2026-10-06 | |
| Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping | CVE-2026-95105 | 2026-10-06 | |
| Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash | CVE-2026-94201 | 2026-10-05 | |
| Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries | CVE-2026-94194 | 2026-09-28 | |
| Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size | CVE-2026-92103 | 2026-09-28 | |
| HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory | CVE-2026-91043 | 2026-09-28 | |
| lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS | CVE-2026-92106 | 2026-09-25 | |
| Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash | CVE-2026-93477 | 2026-09-25 | |
| Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy | CVE-2026-91187 | 2026-09-24 | |
| Refresh tokens accepted as private repository credentials at the CDN | CVE-2026-86698 | 2026-09-22 | |
| mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed | CVE-2026-87119 | 2026-09-22 | |
| Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free | CVE-2026-89420 | 2026-09-22 | |
| Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder |
Erlang
pkg:otp/asn1
|
CVE-2026-65634 | 2026-09-22 |
| SSH daemon allocates unbounded idle session channels, bypassing max_channels |
Erlang
pkg:otp/ssh
|
CVE-2026-68956 | 2026-09-22 |
| TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension |
Erlang
Erlang / ssl
|
CVE-2026-89422 | 2026-09-22 |
| Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections | CVE-2026-82672 | 2026-09-19 | |
| Session id is not renewed on authentication in ash_authentication, allowing session fixation | CVE-2026-86688 | 2026-09-17 | |
| Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement | CVE-2026-76949 | 2026-09-17 | |
| dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover | CVE-2026-91039 | 2026-09-17 | |
| OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication | CVE-2026-88952 | 2026-09-17 | |
| `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication | CVE-2026-85500 | 2026-09-17 |