The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Not Failing Securely ('Failing Open') CWE-636 CWE-636 at MITRE

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

No CVEs to show Total 3
Non-exit on Failed Initialization CWE-455 0 (0.0%)
Classified as CWE-636 itself, not a child weakness 3

CVEs

CVEs for Not Failing Securely ('Failing Open') CWE-636

Summary Publication CVE ID Published
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts CVE-2026-77866 2026-09-15
Ash.Reactor change step fails open, skipping a change when its where guard raises CVE-2026-82744 2026-09-01
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
ghcr.io / livebook-dev/livebook
CVE-2026-68746 2026-08-05
3 CVEs