Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Viewing · CWE-1000
Switch view
CWE-1000 at MITRE
We're looking at the CWE hierarchy through the Research Concepts view.
CVEs
Every CVE in this view
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| Session id is not renewed on authentication in ash_authentication, allowing session fixation | CVE-2026-86688 | 2026-09-17 | |
| Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement | CVE-2026-76949 | 2026-09-17 | |
| dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover | CVE-2026-91039 | 2026-09-17 | |
| OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication | CVE-2026-88952 | 2026-09-17 | |
| `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication | CVE-2026-85500 | 2026-09-17 | |
| Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix | CVE-2026-86533 | 2026-09-17 | |
| Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix | CVE-2026-81632 | 2026-09-17 | |
| Sign-in token minted for one resource accepted by another in AshAuthentication | CVE-2026-80218 | 2026-09-17 | |
| Token revocation record built from unverified JWT claims in AshAuthentication | CVE-2026-78223 | 2026-09-17 | |
| Log injection via an unescaped password reset identity in AshAuthentication | CVE-2026-86522 | 2026-09-17 | |
| Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication | CVE-2026-81637 | 2026-09-17 | |
| Magic link single-use tokens replayable via TOCTOU race in AshAuthentication | CVE-2026-82761 | 2026-09-17 | |
| Confirmation token accepted on any record in AshAuthentication | CVE-2026-82685 | 2026-09-17 | |
| Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in | CVE-2026-82760 | 2026-09-17 | |
| Reversible IP address pseudonymisation in AshAuthentication audit log hash mode | CVE-2026-82759 | 2026-09-17 | |
| Actor record with password digest stored in AshAuthentication audit log entries | CVE-2026-82723 | 2026-09-17 | |
| Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle | CVE-2026-86338 | 2026-09-16 | |
| mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot | CVE-2026-88255 | 2026-09-16 | |
| mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches | CVE-2026-89186 | 2026-09-16 | |
| SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts | CVE-2026-77866 | 2026-09-15 | |
| safeurl validated address is not bound to the request, allowing DNS rebinding | CVE-2026-77972 | 2026-09-15 | |
| AshLua eval read operations can read field-policy-protected fields via aggregates | CVE-2026-78216 | 2026-09-08 | |
| AshAi aggregate tool can read field-policy-protected fields | CVE-2026-78230 | 2026-09-08 | |
| Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata | CVE-2026-82710 | 2026-09-08 | |
| Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata | CVE-2026-82584 | 2026-09-07 |