Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Viewing · CWE-1200
Switch view
CWE-1200 at MITRE
We're looking at the CWE hierarchy through the Weaknesses in the 2019 CWE Top 25 Most Dangerous Software Errors view.
CVEs
Every CVE in this view
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication | CVE-2026-88952 | 2026-09-17 | |
| Sign-in token minted for one resource accepted by another in AshAuthentication | CVE-2026-80218 | 2026-09-17 | |
| ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint | CVE-2026-82758 | 2026-09-07 | |
| httpd parks a request worker indefinitely on a malformed chunk size sent after the headers |
Erlang
pkg:otp/inets
|
CVE-2026-69664 | 2026-09-01 |
| A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer |
Erlang
pkg:otp/erts
|
CVE-2026-75538 | 2026-09-01 |
| httpd applies no timeout while receiving a request body, parking a worker on a stalled client |
Erlang
pkg:otp/inets
|
CVE-2026-71380 | 2026-09-01 |
| Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads | CVE-2026-82743 | 2026-09-01 | |
| Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory | CVE-2026-82742 | 2026-09-01 | |
| Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs | CVE-2026-82740 | 2026-09-01 | |
| Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service | CVE-2026-82738 | 2026-09-01 | |
| Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads | CVE-2026-82737 | 2026-09-01 | |
| Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service | CVE-2026-82735 | 2026-09-01 | |
| Declared argument constraints not enforced on AshTypescript typed controller routes | CVE-2026-82732 | 2026-09-01 | |
| Path traversal in AshAdmin file uploads via unsanitized client filename | CVE-2026-82673 | 2026-08-31 | |
| Stored XSS in AshAdmin relationship typeahead via unescaped label_field content | CVE-2026-77850 | 2026-08-31 | |
| EEx template evaluation of prompt content in AshAi enables remote code execution | CVE-2026-77956 | 2026-08-31 | |
| Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment | CVE-2026-81633 | 2026-08-30 | |
| Cloaked plaintext leaks through a non-sensitive action argument in AshCloak | CVE-2026-81322 | 2026-08-30 | |
| Unsafe deserialization of decrypted terms enables node DoS in AshCloak | CVE-2026-81319 | 2026-08-30 | |
| Doggo vulnerable to cross-site scripting via unescaped date field values | CVE-2026-66353 | 2026-08-27 | |
| Purpose-limited JWT accepted as full bearer authentication in AshAuthentication | CVE-2026-65633 | 2026-08-25 | |
| Reflected XSS in AshAuthentication confirmation and magic link interaction forms | CVE-2026-66882 | 2026-08-25 | |
| Filter expression injection via forged keyset pagination cursor in Ash | CVE-2026-67579 | 2026-08-12 | |
| Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset | CVE-2026-69659 | 2026-08-09 | |
| SQL injection via the :comment option in Postgrex.stream/4 | CVE-2026-66838 | 2026-08-07 |