The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1000 CWE-1000 at MITRE

We're looking at the CWE hierarchy through the Research Concepts view.

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Reflected XSS in oaskit's default HTML error handler CVE-2026-66296 2026-08-03
guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1 CVE-2026-55734 2026-08-01
Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation CVE-2026-55733 2026-08-01
Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys CVE-2026-54894 2026-08-01
Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation CVE-2026-55735 2026-08-01
YAML injection via unescaped newlines in ymlr document comments CVE-2026-65636 2026-07-31
Boruta accepts expired JWT client assertions due to missing exp claim validation CVE-2026-53431 2026-07-30
Boruta dynamic client registration allows creation of over-privileged OAuth clients CVE-2026-65635 2026-07-30
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching CVE-2026-54885 2026-07-30
Insufficient verification of Hex package metadata in Gleam
Gleam
ghcr.io / gleam-lang/gleam
CVE-2026-59247 2026-07-29
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion CVE-2026-65624 2026-07-28
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS CVE-2026-59248 2026-07-28
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
Erlang / erts
CVE-2026-54890 2026-07-27
Denial of service via exponential certificate policy tree growth in path validation
Erlang / public_key
CVE-2026-59251 2026-07-27
Megaco flex scanner buffer overflow via oversized property parm name
Erlang / megaco
CVE-2026-59250 2026-07-27
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
Erlang
Erlang / ssl
CVE-2026-55953 2026-07-27
Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
Erlang / erts
CVE-2026-55737 2026-07-27
Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
Erlang / stdlib
CVE-2026-47078 2026-07-27
epmd permanent DoS via EMFILE on accept(2) in erts
Erlang / erts
CVE-2026-42792 2026-07-27
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
Erlang / ssl
CVE-2026-58227 2026-07-27
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit CVE-2026-65623 2026-07-24
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain CVE-2026-59252 2026-07-17
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment CVE-2026-59694 2026-07-17
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain CVE-2026-59695 2026-07-17
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections CVE-2026-59249 2026-07-16
25 per page · 152 CVEs
Page of 7