Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Viewing · CWE-1435
Switch view
CWE-1435 at MITRE
We're looking at the CWE hierarchy through the Weaknesses in the 2025 CWE Top 25 Most Dangerous Software Weaknesses view.
CVEs
Every CVE in this view
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| Confirmation token accepted on any record in AshAuthentication | CVE-2026-82685 | 2026-09-17 | |
| SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts | CVE-2026-77866 | 2026-09-15 | |
| ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF | CVE-2026-82757 | 2026-09-07 | |
| Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server | CVE-2026-82753 | 2026-09-07 | |
| Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS | CVE-2026-82728 | 2026-09-04 | |
| A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer |
Erlang
pkg:otp/erts
|
CVE-2026-75538 | 2026-09-01 |
| inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
Erlang
pkg:otp/inets
|
CVE-2026-74994 | 2026-09-01 |
| inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception |
Erlang
pkg:otp/inets
|
CVE-2026-74835 | 2026-09-01 |
| httpc memory exhaustion via unbounded response header accumulation |
Erlang
pkg:otp/inets
|
CVE-2026-55951 | 2026-09-01 |
| httpd does not enforce the documented default max_clients connection limit |
Erlang
pkg:otp/inets
|
CVE-2026-70399 | 2026-09-01 |
| Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor | CVE-2026-82747 | 2026-09-01 | |
| Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records | CVE-2026-82749 | 2026-09-01 | |
| Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another | CVE-2026-82748 | 2026-09-01 | |
| Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records | CVE-2026-82746 | 2026-09-01 | |
| ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness | CVE-2026-82745 | 2026-09-01 | |
| Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs | CVE-2026-82740 | 2026-09-01 | |
| Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service | CVE-2026-82738 | 2026-09-01 | |
| Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter | CVE-2026-74837 | 2026-09-01 | |
| Declared argument constraints not enforced on AshTypescript typed controller routes | CVE-2026-82732 | 2026-09-01 | |
| Authorization-redacted field values disclosed through AshTypescript result normalization | CVE-2026-82730 | 2026-09-01 | |
| Unbounded atom creation from typed struct field names in AshTypescript field selector | CVE-2026-77856 | 2026-09-01 | |
| AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data | CVE-2026-82725 | 2026-08-31 | |
| Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain | CVE-2026-82724 | 2026-08-31 | |
| Path traversal in AshAdmin file uploads via unsanitized client filename | CVE-2026-82673 | 2026-08-31 | |
| AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle | CVE-2026-81853 | 2026-08-31 |