Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Viewing · CWE-1000
Switch view
CWE-1000 at MITRE
We're looking at the CWE hierarchy through the Research Concepts view.
CVEs
Every CVE in this view
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation | CVE-2026-82750 | 2026-09-06 | |
| Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning | CVE-2026-82751 | 2026-09-06 | |
| Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length | CVE-2026-82752 | 2026-09-05 | |
| Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS | CVE-2026-82728 | 2026-09-04 | |
| Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS | CVE-2026-82729 | 2026-09-04 | |
| httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
Erlang
pkg:otp/inets
|
CVE-2026-69664 | 2026-09-01 |
| eldap does not bound the port component of a referral URL before integer conversion |
Erlang
pkg:otp/eldap
|
CVE-2026-70409 | 2026-09-01 |
| snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields |
Erlang
pkg:otp/snmp
|
CVE-2026-70405 | 2026-09-01 |
| httpd mod_auth directory protection bypassed by a doubled slash in the request path |
Erlang
pkg:otp/inets
|
CVE-2026-66835 | 2026-09-01 |
| httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems |
Erlang
pkg:otp/inets
|
CVE-2026-73270 | 2026-09-01 |
| A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer |
Erlang
pkg:otp/erts
|
CVE-2026-75538 | 2026-09-01 |
| inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
Erlang
pkg:otp/inets
|
CVE-2026-74994 | 2026-09-01 |
| inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
Erlang
pkg:otp/inets
|
CVE-2026-74835 | 2026-09-01 |
| inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
Erlang
pkg:otp/inets
|
CVE-2026-73812 | 2026-09-01 |
| inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i |
Erlang
pkg:otp/inets
|
CVE-2026-73276 | 2026-09-01 |
| inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
Erlang
pkg:otp/inets
|
CVE-2026-66357 | 2026-09-01 |
| uri_string does not bound the port component of a URI before integer conversion |
Erlang
pkg:otp/stdlib
|
CVE-2026-59696 | 2026-09-01 |
| httpc memory exhaustion via unbounded response header accumulation |
Erlang
pkg:otp/inets
|
CVE-2026-55951 | 2026-09-01 |
| httpd applies no timeout while receiving a request body, parking a worker on a stalled client |
Erlang
pkg:otp/inets
|
CVE-2026-71380 | 2026-09-01 |
| httpc does not bound server-supplied numeric header values before integer conversion |
Erlang
pkg:otp/inets
|
CVE-2026-71562 | 2026-09-01 |
| httpd does not enforce the documented default max_clients connection limit |
Erlang
pkg:otp/inets
|
CVE-2026-70399 | 2026-09-01 |
| Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor | CVE-2026-82747 | 2026-09-01 | |
| Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records | CVE-2026-82749 | 2026-09-01 | |
| Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another | CVE-2026-82748 | 2026-09-01 | |
| Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records | CVE-2026-82746 | 2026-09-01 |