The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1000 CWE-1000 at MITRE

We're looking at the CWE hierarchy through the Research Concepts view.

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Session id is not renewed on authentication in ash_authentication, allowing session fixation CVE-2026-86688 2026-09-17
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement CVE-2026-76949 2026-09-17
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover CVE-2026-91039 2026-09-17
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication CVE-2026-85500 2026-09-17
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix CVE-2026-86533 2026-09-17
Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix CVE-2026-81632 2026-09-17
Sign-in token minted for one resource accepted by another in AshAuthentication CVE-2026-80218 2026-09-17
Token revocation record built from unverified JWT claims in AshAuthentication CVE-2026-78223 2026-09-17
Log injection via an unescaped password reset identity in AshAuthentication CVE-2026-86522 2026-09-17
Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication CVE-2026-81637 2026-09-17
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication CVE-2026-82761 2026-09-17
Confirmation token accepted on any record in AshAuthentication CVE-2026-82685 2026-09-17
Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in CVE-2026-82760 2026-09-17
Reversible IP address pseudonymisation in AshAuthentication audit log hash mode CVE-2026-82759 2026-09-17
Actor record with password digest stored in AshAuthentication audit log entries CVE-2026-82723 2026-09-17
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle CVE-2026-86338 2026-09-16
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot CVE-2026-88255 2026-09-16
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches CVE-2026-89186 2026-09-16
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts CVE-2026-77866 2026-09-15
safeurl validated address is not bound to the request, allowing DNS rebinding CVE-2026-77972 2026-09-15
AshLua eval read operations can read field-policy-protected fields via aggregates CVE-2026-78216 2026-09-08
AshAi aggregate tool can read field-policy-protected fields CVE-2026-78230 2026-09-08
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata CVE-2026-82710 2026-09-08
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata CVE-2026-82584 2026-09-07
25 per page · 304 CVEs
Page of 13