The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1387 CWE-1387 at MITRE

We're looking at the CWE hierarchy through the Weaknesses in the 2022 CWE Top 25 Most Dangerous Software Weaknesses view.

Uncontrolled Resource Consumption: 17 CVEs (24.6%) — click to drill down Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): 9 CVEs (13.0%) — click to drill down Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'): 9 CVEs (13.0%) — click to drill down Deserialization of Untrusted Data: 5 CVEs (7.2%) — click to drill down Server-Side Request Forgery (SSRF): 5 CVEs (7.2%) — click to drill down Improper Input Validation: 4 CVEs (5.8%) — click to drill down Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): 4 CVEs (5.8%) — click to drill down Improper Authentication: 4 CVEs (5.8%) — click to drill down Improper Control of Generation of Code ('Code Injection'): 2 CVEs (2.9%) — click to drill down Integer Overflow or Wraparound: 2 CVEs (2.9%) — click to drill down Cross-Site Request Forgery (CSRF): 2 CVEs (2.9%) — click to drill down Out-of-bounds Write: 2 CVEs (2.9%) — click to drill down Missing Authorization: 2 CVEs (2.9%) — click to drill down Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'): 1 CVEs (1.4%) — click to drill down Improper Restriction of XML External Entity Reference: 1 CVEs (1.4%) — click to drill down Improper Neutralization of Special Elements used in a Command ('Command Injection'): 0 CVEs (0.0%) — click to drill down Improper Restriction of Operations within the Bounds of a Memory Buffer: 0 CVEs (0.0%) — click to drill down Out-of-bounds Read: 0 CVEs (0.0%) — click to drill down Incorrect Default Permissions: 0 CVEs (0.0%) — click to drill down Missing Authentication for Critical Function: 0 CVEs (0.0%) — click to drill down Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'): 0 CVEs (0.0%) — click to drill down Use After Free: 0 CVEs (0.0%) — click to drill down Unrestricted Upload of File with Dangerous Type: 0 CVEs (0.0%) — click to drill down NULL Pointer Dereference: 0 CVEs (0.0%) — click to drill down Use of Hard-coded Credentials: 0 CVEs (0.0%) — click to drill down Total 67
Uncontrolled Resource Consumption CWE-400 17 (24.6%) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-22 9 (13.0%) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 9 (13.0%) Deserialization of Untrusted Data CWE-502 5 (7.2%) Server-Side Request Forgery (SSRF) CWE-918 5 (7.2%) Improper Input Validation CWE-20 4 (5.8%) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89 4 (5.8%) Improper Authentication CWE-287 4 (5.8%) Improper Control of Generation of Code ('Code Injection') CWE-94 2 (2.9%) Integer Overflow or Wraparound CWE-190 2 (2.9%) Cross-Site Request Forgery (CSRF) CWE-352 2 (2.9%) Out-of-bounds Write CWE-787 2 (2.9%) Missing Authorization CWE-862 2 (2.9%) Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78 1 (1.4%) Improper Restriction of XML External Entity Reference CWE-611 1 (1.4%) Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-77 0 (0.0%) Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-119 0 (0.0%) Out-of-bounds Read CWE-125 0 (0.0%) Incorrect Default Permissions CWE-276 0 (0.0%) Missing Authentication for Critical Function CWE-306 0 (0.0%) Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-362 0 (0.0%) Use After Free CWE-416 0 (0.0%) Unrestricted Upload of File with Dangerous Type CWE-434 0 (0.0%) NULL Pointer Dereference CWE-476 0 (0.0%) Use of Hard-coded Credentials CWE-798 0 (0.0%)

CVEs

Every CVE in this view

Summary Publication CVE ID Published
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication CVE-2026-88952 2026-09-17
Sign-in token minted for one resource accepted by another in AshAuthentication CVE-2026-80218 2026-09-17
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts CVE-2026-77866 2026-09-15
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint CVE-2026-82758 2026-09-07
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF CVE-2026-82757 2026-09-07
A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
Erlang
pkg:otp/erts
CVE-2026-75538 2026-09-01
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records CVE-2026-82746 2026-09-01
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads CVE-2026-82743 2026-09-01
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory CVE-2026-82742 2026-09-01
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs CVE-2026-82740 2026-09-01
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service CVE-2026-82738 2026-09-01
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads CVE-2026-82737 2026-09-01
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service CVE-2026-82735 2026-09-01
Declared argument constraints not enforced on AshTypescript typed controller routes CVE-2026-82732 2026-09-01
Path traversal in AshAdmin file uploads via unsanitized client filename CVE-2026-82673 2026-08-31
Stored XSS in AshAdmin relationship typeahead via unescaped label_field content CVE-2026-77850 2026-08-31
EEx template evaluation of prompt content in AshAi enables remote code execution CVE-2026-77956 2026-08-31
Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment CVE-2026-81633 2026-08-30
Unsafe deserialization of decrypted terms enables node DoS in AshCloak CVE-2026-81319 2026-08-30
Doggo vulnerable to cross-site scripting via unescaped date field values CVE-2026-66353 2026-08-27
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication CVE-2026-65633 2026-08-25
Reflected XSS in AshAuthentication confirmation and magic link interaction forms CVE-2026-66882 2026-08-25
Filter expression injection via forged keyset pagination cursor in Ash CVE-2026-67579 2026-08-12
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset CVE-2026-69659 2026-08-09
SQL injection via the :comment option in Postgrex.stream/4 CVE-2026-66838 2026-08-07
25 per page · 67 CVEs
Page of 3