The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1340 CWE-1340 at MITRE

We're looking at the CWE hierarchy through the CISQ Data Protection Measures view.

Improper Access Control: 32 CVEs (42.1%) — click to drill down Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): 12 CVEs (15.8%) — click to drill down Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'): 9 CVEs (11.8%) — click to drill down Deserialization of Untrusted Data: 5 CVEs (6.6%) — click to drill down Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): 4 CVEs (5.3%) — click to drill down XML Injection (aka Blind XPath Injection): 2 CVEs (2.6%) — click to drill down Improper Restriction of Operations within the Bounds of a Memory Buffer: 2 CVEs (2.6%) — click to drill down Improper Resource Shutdown or Release: 2 CVEs (2.6%) — click to drill down Improper Protection of Alternate Path: 2 CVEs (2.6%) — click to drill down Improperly Controlled Modification of Dynamically-Determined Object Attributes: 2 CVEs (2.6%) — click to drill down Improper Neutralization of Special Elements used in a Command ('Command Injection'): 1 CVEs (1.3%) — click to drill down Improper Restriction of XML External Entity Reference: 1 CVEs (1.3%) — click to drill down Operation on a Resource after Expiration or Release: 1 CVEs (1.3%) — click to drill down Incorrect Conversion between Numeric Types: 1 CVEs (1.3%) — click to drill down Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection'): 0 CVEs (0.0%) — click to drill down Improper Control of Resource Identifiers ('Resource Injection'): 0 CVEs (0.0%) — click to drill down Improper Validation of Array Index: 0 CVEs (0.0%) — click to drill down Use of Externally-Controlled Format String: 0 CVEs (0.0%) — click to drill down Improper Null Termination: 0 CVEs (0.0%) — click to drill down Exposure of Sensitive Information Due to Incompatible Policies: 0 CVEs (0.0%) — click to drill down Missing Encryption of Sensitive Data: 0 CVEs (0.0%) — click to drill down Exposure of Private Personal Information to an Unauthorized Actor: 0 CVEs (0.0%) — click to drill down Unrestricted Upload of File with Dangerous Type: 0 CVEs (0.0%) — click to drill down Return of Stack Variable Address: 0 CVEs (0.0%) — click to drill down Unchecked Input for Loop Condition: 0 CVEs (0.0%) — click to drill down Improper Neutralization of Data within XPath Expressions ('XPath Injection'): 0 CVEs (0.0%) — click to drill down Improper Neutralization of Data within XQuery Expressions ('XQuery Injection'): 0 CVEs (0.0%) — click to drill down Improper Synchronization: 0 CVEs (0.0%) — click to drill down Improper Initialization: 0 CVEs (0.0%) — click to drill down Incorrect Calculation: 0 CVEs (0.0%) — click to drill down Improper Check or Handling of Exceptional Conditions: 0 CVEs (0.0%) — click to drill down Incorrect Type Conversion or Cast: 0 CVEs (0.0%) — click to drill down Incorrect Permission Assignment for Critical Resource: 0 CVEs (0.0%) — click to drill down Use of Hard-coded Credentials: 0 CVEs (0.0%) — click to drill down Use of Uninitialized Resource: 0 CVEs (0.0%) — click to drill down Initialization with Hard-Coded Network Resource Configuration Data: 0 CVEs (0.0%) — click to drill down Total 74
Improper Access Control CWE-284 32 (42.1%) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-22 12 (15.8%) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 9 (11.8%) Deserialization of Untrusted Data CWE-502 5 (6.6%) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89 4 (5.3%) XML Injection (aka Blind XPath Injection) CWE-91 2 (2.6%) Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-119 2 (2.6%) Improper Resource Shutdown or Release CWE-404 2 (2.6%) Improper Protection of Alternate Path CWE-424 2 (2.6%) Improperly Controlled Modification of Dynamically-Determined Object Attributes CWE-915 2 (2.6%) Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-77 1 (1.3%) Improper Restriction of XML External Entity Reference CWE-611 1 (1.3%) Operation on a Resource after Expiration or Release CWE-672 1 (1.3%) Incorrect Conversion between Numeric Types CWE-681 1 (1.3%) Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CWE-90 0 (0.0%) Improper Control of Resource Identifiers ('Resource Injection') CWE-99 0 (0.0%) Improper Validation of Array Index CWE-129 0 (0.0%) Use of Externally-Controlled Format String CWE-134 0 (0.0%) Improper Null Termination CWE-170 0 (0.0%) Exposure of Sensitive Information Due to Incompatible Policies CWE-213 0 (0.0%) Missing Encryption of Sensitive Data CWE-311 0 (0.0%) Exposure of Private Personal Information to an Unauthorized Actor CWE-359 0 (0.0%) Unrestricted Upload of File with Dangerous Type CWE-434 0 (0.0%) Return of Stack Variable Address CWE-562 0 (0.0%) Unchecked Input for Loop Condition CWE-606 0 (0.0%) Improper Neutralization of Data within XPath Expressions ('XPath Injection') CWE-643 0 (0.0%) Improper Neutralization of Data within XQuery Expressions ('XQuery Injection') CWE-652 0 (0.0%) Improper Synchronization CWE-662 0 (0.0%) Improper Initialization CWE-665 0 (0.0%) Incorrect Calculation CWE-682 0 (0.0%) Improper Check or Handling of Exceptional Conditions CWE-703 0 (0.0%) Incorrect Type Conversion or Cast CWE-704 0 (0.0%) Incorrect Permission Assignment for Critical Resource CWE-732 0 (0.0%) Use of Hard-coded Credentials CWE-798 0 (0.0%) Use of Uninitialized Resource CWE-908 0 (0.0%) Initialization with Hard-Coded Network Resource Configuration Data CWE-1051 0 (0.0%)

CVEs

Every CVE in this view

Summary Publication CVE ID Published
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
Sign-in token minted for one resource accepted by another in AshAuthentication CVE-2026-80218 2026-09-17
Confirmation token accepted on any record in AshAuthentication CVE-2026-82685 2026-09-17
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes CVE-2026-82586 2026-09-07
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint CVE-2026-82758 2026-09-07
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls CVE-2026-82754 2026-09-07
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
Erlang
pkg:otp/inets
CVE-2026-69664 2026-09-01
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Erlang
pkg:otp/inets
CVE-2026-74994 2026-09-01
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
CVE-2026-71380 2026-09-01
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor CVE-2026-82747 2026-09-01
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records CVE-2026-82749 2026-09-01
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another CVE-2026-82748 2026-09-01
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records CVE-2026-82746 2026-09-01
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness CVE-2026-82745 2026-09-01
Authorization-redacted field values disclosed through AshTypescript result normalization CVE-2026-82730 2026-09-01
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data CVE-2026-82725 2026-08-31
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain CVE-2026-82724 2026-08-31
Path traversal in AshAdmin file uploads via unsanitized client filename CVE-2026-82673 2026-08-31
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle CVE-2026-81853 2026-08-31
Stored XSS in AshAdmin relationship typeahead via unescaped label_field content CVE-2026-77850 2026-08-31
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records CVE-2026-82564 2026-08-31
Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read CVE-2026-80223 2026-08-30
Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification CVE-2026-81643 2026-08-30
Unsafe deserialization of decrypted terms enables node DoS in AshCloak CVE-2026-81319 2026-08-30
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql CVE-2026-77454 2026-08-30
25 per page · 74 CVEs
Page of 3