The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Improper Authentication CWE-287 CWE-287 at MITRE

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CVEs

CVEs for Improper Authentication CWE-287

Summary Publication CVE ID Published
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement CVE-2026-76949 2026-09-17
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover CVE-2026-91039 2026-09-17
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication CVE-2026-85500 2026-09-17
Sign-in token minted for one resource accepted by another in AshAuthentication CVE-2026-80218 2026-09-17
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint CVE-2026-82758 2026-09-07
httpd mod_auth directory protection bypassed by a doubled slash in the request path
Erlang
pkg:otp/inets
CVE-2026-66835 2026-09-01
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication CVE-2026-65633 2026-08-25
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions CVE-2026-53424 2026-08-20
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay CVE-2026-67581 2026-08-19
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay CVE-2026-73136 2026-08-19
Boruta accepts expired JWT client assertions due to missing exp claim validation CVE-2026-53431 2026-07-30
Missing ID token claim validation in ueberauth_apple allows account takeover CVE-2026-55954 2026-07-14
DTLS server cookie bypass during startup window due to empty initial cookie secret
Erlang / ssl
CVE-2026-54887 2026-07-02
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching CVE-2026-49757 2026-06-15
ex_aws_sns SigningCertURL not validated in verify_message/1 CVE-2026-47074 2026-05-28
nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
Erlang / public_key
CVE-2026-42790 2026-05-27
OCSP responder certificate validity period not checked in public_key
Erlang / public_key
CVE-2026-42791 2026-05-27
Non-CA certificate accepted as intermediate issuer in public_key path validation
Erlang / public_key
CVE-2026-42789 2026-05-27
OCSP designated-responder authorization bypass via missing signature verification
Erlang / public_key
Erlang / ssl
CVE-2026-32144 2026-04-07
20 CVEs