The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1000 CWE-1000 at MITRE

We're looking at the CWE hierarchy through the Research Concepts view.

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation CVE-2026-82750 2026-09-06
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning CVE-2026-82751 2026-09-06
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length CVE-2026-82752 2026-09-05
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS CVE-2026-82728 2026-09-04
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS CVE-2026-82729 2026-09-04
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
Erlang
pkg:otp/inets
CVE-2026-69664 2026-09-01
eldap does not bound the port component of a referral URL before integer conversion
Erlang
pkg:otp/eldap
CVE-2026-70409 2026-09-01
snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
Erlang
pkg:otp/snmp
CVE-2026-70405 2026-09-01
httpd mod_auth directory protection bypassed by a doubled slash in the request path
Erlang
pkg:otp/inets
CVE-2026-66835 2026-09-01
httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
Erlang
pkg:otp/inets
CVE-2026-73270 2026-09-01
A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
Erlang
pkg:otp/erts
CVE-2026-75538 2026-09-01
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Erlang
pkg:otp/inets
CVE-2026-74994 2026-09-01
inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
Erlang
pkg:otp/inets
CVE-2026-74835 2026-09-01
inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
Erlang
pkg:otp/inets
CVE-2026-73812 2026-09-01
inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Erlang
pkg:otp/inets
CVE-2026-73276 2026-09-01
inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
Erlang
pkg:otp/inets
CVE-2026-66357 2026-09-01
uri_string does not bound the port component of a URI before integer conversion
Erlang
pkg:otp/stdlib
CVE-2026-59696 2026-09-01
httpc memory exhaustion via unbounded response header accumulation
Erlang
pkg:otp/inets
CVE-2026-55951 2026-09-01
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
CVE-2026-71380 2026-09-01
httpc does not bound server-supplied numeric header values before integer conversion
Erlang
pkg:otp/inets
CVE-2026-71562 2026-09-01
httpd does not enforce the documented default max_clients connection limit
Erlang
pkg:otp/inets
CVE-2026-70399 2026-09-01
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor CVE-2026-82747 2026-09-01
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records CVE-2026-82749 2026-09-01
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another CVE-2026-82748 2026-09-01
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records CVE-2026-82746 2026-09-01
25 per page · 271 CVEs
Page of 11