The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Improper Resource Shutdown or Release CWE-404 CWE-404 at MITRE

The product does not release or incorrectly releases a resource before it is made available for re-use.

CVEs

CVEs for Improper Resource Shutdown or Release CWE-404

Summary Publication CVE ID Published
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
Erlang
pkg:otp/inets
CVE-2026-69664 2026-09-01
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
CVE-2026-71380 2026-09-01
Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service CVE-2026-53429 2026-06-29
3 CVEs