The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-884 CWE-884 at MITRE

We're looking at the CWE hierarchy through the CWE Cross-section view.

Allocation of Resources Without Limits or Throttling: 48 CVEs (24.2%) — click to drill down Incorrect Authorization: 18 CVEs (9.1%) — click to drill down Uncontrolled Resource Consumption: 17 CVEs (8.6%) — click to drill down Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): 9 CVEs (4.5%) — click to drill down Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'): 9 CVEs (4.5%) — click to drill down Inefficient Algorithmic Complexity: 8 CVEs (4.0%) — click to drill down Generation of Error Message Containing Sensitive Information: 7 CVEs (3.5%) — click to drill down Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'): 7 CVEs (3.5%) — click to drill down URL Redirection to Untrusted Site ('Open Redirect'): 6 CVEs (3.0%) — click to drill down Improper Handling of Highly Compressed Data (Data Amplification): 5 CVEs (2.5%) — click to drill down Deserialization of Untrusted Data: 5 CVEs (2.5%) — click to drill down Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): 4 CVEs (2.0%) — click to drill down Authentication Bypass by Spoofing: 4 CVEs (2.0%) — click to drill down Authentication Bypass by Capture-replay: 4 CVEs (2.0%) — click to drill down Time-of-check Time-of-use (TOCTOU) Race Condition: 4 CVEs (2.0%) — click to drill down Uncontrolled Recursion: 4 CVEs (2.0%) — click to drill down Loop with Unreachable Exit Condition ('Infinite Loop'): 4 CVEs (2.0%) — click to drill down Relative Path Traversal: 3 CVEs (1.5%) — click to drill down Improper Verification of Cryptographic Signature: 3 CVEs (1.5%) — click to drill down Improper Control of Generation of Code ('Code Injection'): 2 CVEs (1.0%) — click to drill down Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'): 2 CVEs (1.0%) — click to drill down Integer Overflow or Wraparound: 2 CVEs (1.0%) — click to drill down Cleartext Storage of Sensitive Information: 2 CVEs (1.0%) — click to drill down Cross-Site Request Forgery (CSRF): 2 CVEs (1.0%) — click to drill down Missing Release of Resource after Effective Lifetime: 2 CVEs (1.0%) — click to drill down Missing Authorization: 2 CVEs (1.0%) — click to drill down Improper Link Resolution Before File Access ('Link Following'): 1 CVEs (0.5%) — click to drill down Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'): 1 CVEs (0.5%) — click to drill down Improper Output Neutralization for Logs: 1 CVEs (0.5%) — click to drill down Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'): 1 CVEs (0.5%) — click to drill down Improper Handling of Alternate Encoding: 1 CVEs (0.5%) — click to drill down Integer Underflow (Wrap or Wraparound): 1 CVEs (0.5%) — click to drill down Unchecked Return Value: 1 CVEs (0.5%) — click to drill down Improper Following of a Certificate's Chain of Trust: 1 CVEs (0.5%) — click to drill down Improper Validation of Integrity Check Value: 1 CVEs (0.5%) — click to drill down Download of Code Without Integrity Check: 1 CVEs (0.5%) — click to drill down Operation on a Resource after Expiration or Release: 1 CVEs (0.5%) — click to drill down Reliance on Untrusted Inputs in a Security Decision: 1 CVEs (0.5%) — click to drill down Inclusion of Functionality from Untrusted Control Sphere: 1 CVEs (0.5%) — click to drill down Inappropriate Encoding for Output Context: 1 CVEs (0.5%) — click to drill down Improper Enforcement of Behavioral Workflow: 1 CVEs (0.5%) — click to drill down Compiler Removal of Code to Clear Buffers: 0 CVEs (0.0%) — click to drill down Absolute Path Traversal: 0 CVEs (0.0%) — click to drill down Improper Resolution of Path Equivalence: 0 CVEs (0.0%) — click to drill down Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'): 0 CVEs (0.0%) — click to drill down Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection'): 0 CVEs (0.0%) — click to drill down Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'): 0 CVEs (0.0%) — click to drill down Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection'): 0 CVEs (0.0%) — click to drill down Improper Control of Resource Identifiers ('Resource Injection'): 0 CVEs (0.0%) — click to drill down Improper Validation of Array Index: 0 CVEs (0.0%) — click to drill down Incorrect Calculation of Buffer Size: 0 CVEs (0.0%) — click to drill down Use of Externally-Controlled Format String: 0 CVEs (0.0%) — click to drill down Incorrect Calculation of Multi-Byte String Length: 0 CVEs (0.0%) — click to drill down Improper Null Termination: 0 CVEs (0.0%) — click to drill down Double Decoding of the Same Data: 0 CVEs (0.0%) — click to drill down Improper Handling of Mixed Encoding: 0 CVEs (0.0%) — click to drill down Incorrect Behavior Order: Early Validation: 0 CVEs (0.0%) — click to drill down Incorrect Regular Expression: 0 CVEs (0.0%) — click to drill down Off-by-one Error: 0 CVEs (0.0%) — click to drill down Observable Discrepancy: 0 CVEs (0.0%) — click to drill down Improper Removal of Sensitive Information Before Storage or Transfer: 0 CVEs (0.0%) — click to drill down Truncation of Security-relevant Information: 0 CVEs (0.0%) — click to drill down Omission of Security-relevant Information: 0 CVEs (0.0%) — click to drill down Improper Handling of Syntactically Invalid Structure: 0 CVEs (0.0%) — click to drill down Improper Clearing of Heap Memory Before Release ('Heap Inspection'): 0 CVEs (0.0%) — click to drill down Uncaught Exception: 0 CVEs (0.0%) — click to drill down Execution with Unnecessary Privileges: 0 CVEs (0.0%) — click to drill down Incorrect Check of Function Return Value: 0 CVEs (0.0%) — click to drill down Not Using Password Aging: 0 CVEs (0.0%) — click to drill down Password Aging with Long Expiration: 0 CVEs (0.0%) — click to drill down Incorrect Privilege Assignment: 0 CVEs (0.0%) — click to drill down Privilege Defined With Unsafe Actions: 0 CVEs (0.0%) — click to drill down Privilege Chaining: 0 CVEs (0.0%) — click to drill down Privilege Context Switching Error: 0 CVEs (0.0%) — click to drill down Privilege Dropping / Lowering Errors: 0 CVEs (0.0%) — click to drill down Improper Check for Dropped Privileges: 0 CVEs (0.0%) — click to drill down Unverified Ownership: 0 CVEs (0.0%) — click to drill down Improper Check for Certificate Revocation: 0 CVEs (0.0%) — click to drill down Channel Accessible by Non-Endpoint: 0 CVEs (0.0%) — click to drill down Reflection Attack in an Authentication Protocol: 0 CVEs (0.0%) — click to drill down Missing Critical Step in Authentication: 0 CVEs (0.0%) — click to drill down Missing Authentication for Critical Function: 0 CVEs (0.0%) — click to drill down Improper Restriction of Excessive Authentication Attempts: 0 CVEs (0.0%) — click to drill down Use of Single-factor Authentication: 0 CVEs (0.0%) — click to drill down Cleartext Transmission of Sensitive Information: 0 CVEs (0.0%) — click to drill down Key Exchange without Entity Authentication: 0 CVEs (0.0%) — click to drill down Reusing a Nonce, Key Pair in Encryption: 0 CVEs (0.0%) — click to drill down Missing Cryptographic Step: 0 CVEs (0.0%) — click to drill down Use of a Broken or Risky Cryptographic Algorithm: 0 CVEs (0.0%) — click to drill down Insufficient Entropy: 0 CVEs (0.0%) — click to drill down Small Space of Random Values: 0 CVEs (0.0%) — click to drill down Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG): 0 CVEs (0.0%) — click to drill down Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG): 0 CVEs (0.0%) — click to drill down Predictable from Observable State: 0 CVEs (0.0%) — click to drill down Use of Less Trusted Source: 0 CVEs (0.0%) — click to drill down Acceptance of Extraneous Untrusted Data With Trusted Data: 0 CVEs (0.0%) — click to drill down Missing Support for Integrity Check: 0 CVEs (0.0%) — click to drill down Signal Handler Race Condition: 0 CVEs (0.0%) — click to drill down Divide By Zero: 0 CVEs (0.0%) — click to drill down Detection of Error Condition Without Action: 0 CVEs (0.0%) — click to drill down Missing Report of Error Condition: 0 CVEs (0.0%) — click to drill down Return of Wrong Status Code: 0 CVEs (0.0%) — click to drill down Insufficient Control of Network Message Volume (Network Amplification): 0 CVEs (0.0%) — click to drill down Incorrect Behavior Order: Early Amplification: 0 CVEs (0.0%) — click to drill down Unrestricted Upload of File with Dangerous Type: 0 CVEs (0.0%) — click to drill down User Interface (UI) Misrepresentation of Critical Information: 0 CVEs (0.0%) — click to drill down Insecure Default Variable Initialization: 0 CVEs (0.0%) — click to drill down External Initialization of Trusted Variables or Data Stores: 0 CVEs (0.0%) — click to drill down Non-exit on Failed Initialization: 0 CVEs (0.0%) — click to drill down Missing Initialization of a Variable: 0 CVEs (0.0%) — click to drill down Use of sizeof() on a Pointer Type: 0 CVEs (0.0%) — click to drill down Incorrect Pointer Scaling: 0 CVEs (0.0%) — click to drill down Use of Pointer Subtraction to Determine Size: 0 CVEs (0.0%) — click to drill down Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection'): 0 CVEs (0.0%) — click to drill down NULL Pointer Dereference: 0 CVEs (0.0%) — click to drill down Missing Default Case in Multiple Condition Expression: 0 CVEs (0.0%) — click to drill down Use of Incorrect Operator: 0 CVEs (0.0%) — click to drill down Incorrect Block Delimitation: 0 CVEs (0.0%) — click to drill down Omitted Break Statement in Switch: 0 CVEs (0.0%) — click to drill down Comparison of Classes by Name: 0 CVEs (0.0%) — click to drill down Private Data Structure Returned From A Public Method: 0 CVEs (0.0%) — click to drill down Public Data Assigned to Private Array-Typed Field: 0 CVEs (0.0%) — click to drill down Cloneable Class Containing Sensitive Information: 0 CVEs (0.0%) — click to drill down Serializable Class Containing Sensitive Data: 0 CVEs (0.0%) — click to drill down Weak Password Requirements: 0 CVEs (0.0%) — click to drill down Insufficiently Protected Credentials: 0 CVEs (0.0%) — click to drill down Suspicious Comment: 0 CVEs (0.0%) — click to drill down Use of Hard-coded, Security-relevant Constants: 0 CVEs (0.0%) — click to drill down Dead Code: 0 CVEs (0.0%) — click to drill down Assignment to Variable without Use: 0 CVEs (0.0%) — click to drill down Unsynchronized Access to Shared Data in a Multithreaded Context: 0 CVEs (0.0%) — click to drill down Assignment of a Fixed Address to a Pointer: 0 CVEs (0.0%) — click to drill down Comparison of Object References Instead of Object Contents: 0 CVEs (0.0%) — click to drill down Client-Side Enforcement of Server-Side Security: 0 CVEs (0.0%) — click to drill down Multiple Binds to the Same Port: 0 CVEs (0.0%) — click to drill down Reachable Assertion: 0 CVEs (0.0%) — click to drill down Variable Extraction Error: 0 CVEs (0.0%) — click to drill down Dynamic Variable Evaluation: 0 CVEs (0.0%) — click to drill down Function Call with Incorrectly Specified Arguments: 0 CVEs (0.0%) — click to drill down External Control of Critical State Data: 0 CVEs (0.0%) — click to drill down Incorrect Use of Privileged APIs: 0 CVEs (0.0%) — click to drill down Improper Locking: 0 CVEs (0.0%) — click to drill down Use of Potentially Dangerous Function: 0 CVEs (0.0%) — click to drill down Incorrect Conversion between Numeric Types: 0 CVEs (0.0%) — click to drill down Execution After Redirect (EAR): 0 CVEs (0.0%) — click to drill down Incorrect Ownership Assignment: 0 CVEs (0.0%) — click to drill down Incorrect Permission Assignment for Critical Resource: 0 CVEs (0.0%) — click to drill down Missing Custom Error Page: 0 CVEs (0.0%) — click to drill down Release of Invalid Pointer or Reference: 0 CVEs (0.0%) — click to drill down Operator Precedence Logic Error: 0 CVEs (0.0%) — click to drill down Access of Memory Location Before Start of Buffer: 0 CVEs (0.0%) — click to drill down Access of Memory Location After End of Buffer: 0 CVEs (0.0%) — click to drill down Use of Hard-coded Credentials: 0 CVEs (0.0%) — click to drill down Buffer Access with Incorrect Length Value: 0 CVEs (0.0%) — click to drill down Untrusted Pointer Dereference: 0 CVEs (0.0%) — click to drill down Expired Pointer Dereference: 0 CVEs (0.0%) — click to drill down Numeric Range Comparison Without Minimum Check: 0 CVEs (0.0%) — click to drill down Total 189
Allocation of Resources Without Limits or Throttling CWE-770 48 (24.2%) Incorrect Authorization CWE-863 18 (9.1%) Uncontrolled Resource Consumption CWE-400 17 (8.6%) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-22 9 (4.5%) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 9 (4.5%) Inefficient Algorithmic Complexity CWE-407 8 (4.0%) Generation of Error Message Containing Sensitive Information CWE-209 7 (3.5%) Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE-444 7 (3.5%) URL Redirection to Untrusted Site ('Open Redirect') CWE-601 6 (3.0%) Improper Handling of Highly Compressed Data (Data Amplification) CWE-409 5 (2.5%) Deserialization of Untrusted Data CWE-502 5 (2.5%) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89 4 (2.0%) Authentication Bypass by Spoofing CWE-290 4 (2.0%) Authentication Bypass by Capture-replay CWE-294 4 (2.0%) Time-of-check Time-of-use (TOCTOU) Race Condition CWE-367 4 (2.0%) Uncontrolled Recursion CWE-674 4 (2.0%) Loop with Unreachable Exit Condition ('Infinite Loop') CWE-835 4 (2.0%) Relative Path Traversal CWE-23 3 (1.5%) Improper Verification of Cryptographic Signature CWE-347 3 (1.5%) Improper Control of Generation of Code ('Code Injection') CWE-94 2 (1.0%) Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') CWE-113 2 (1.0%) Integer Overflow or Wraparound CWE-190 2 (1.0%) Cleartext Storage of Sensitive Information CWE-312 2 (1.0%) Cross-Site Request Forgery (CSRF) CWE-352 2 (1.0%) Missing Release of Resource after Effective Lifetime CWE-772 2 (1.0%) Missing Authorization CWE-862 2 (1.0%) Improper Link Resolution Before File Access ('Link Following') CWE-59 1 (0.5%) Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78 1 (0.5%) Improper Output Neutralization for Logs CWE-117 1 (0.5%) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-120 1 (0.5%) Improper Handling of Alternate Encoding CWE-173 1 (0.5%) Integer Underflow (Wrap or Wraparound) CWE-191 1 (0.5%) Unchecked Return Value CWE-252 1 (0.5%) Improper Following of a Certificate's Chain of Trust CWE-296 1 (0.5%) Improper Validation of Integrity Check Value CWE-354 1 (0.5%) Download of Code Without Integrity Check CWE-494 1 (0.5%) Operation on a Resource after Expiration or Release CWE-672 1 (0.5%) Reliance on Untrusted Inputs in a Security Decision CWE-807 1 (0.5%) Inclusion of Functionality from Untrusted Control Sphere CWE-829 1 (0.5%) Inappropriate Encoding for Output Context CWE-838 1 (0.5%) Improper Enforcement of Behavioral Workflow CWE-841 1 (0.5%) Compiler Removal of Code to Clear Buffers CWE-14 0 (0.0%) Absolute Path Traversal CWE-36 0 (0.0%) Improper Resolution of Path Equivalence CWE-41 0 (0.0%) Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') CWE-88 0 (0.0%) Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CWE-90 0 (0.0%) Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') CWE-95 0 (0.0%) Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') CWE-96 0 (0.0%) Improper Control of Resource Identifiers ('Resource Injection') CWE-99 0 (0.0%) Improper Validation of Array Index CWE-129 0 (0.0%) Incorrect Calculation of Buffer Size CWE-131 0 (0.0%) Use of Externally-Controlled Format String CWE-134 0 (0.0%) Incorrect Calculation of Multi-Byte String Length CWE-135 0 (0.0%) Improper Null Termination CWE-170 0 (0.0%) Double Decoding of the Same Data CWE-174 0 (0.0%) Improper Handling of Mixed Encoding CWE-175 0 (0.0%) Incorrect Behavior Order: Early Validation CWE-179 0 (0.0%) Incorrect Regular Expression CWE-185 0 (0.0%) Off-by-one Error CWE-193 0 (0.0%) Observable Discrepancy CWE-203 0 (0.0%) Improper Removal of Sensitive Information Before Storage or Transfer CWE-212 0 (0.0%) Truncation of Security-relevant Information CWE-222 0 (0.0%) Omission of Security-relevant Information CWE-223 0 (0.0%) Improper Handling of Syntactically Invalid Structure CWE-228 0 (0.0%) Improper Clearing of Heap Memory Before Release ('Heap Inspection') CWE-244 0 (0.0%) Uncaught Exception CWE-248 0 (0.0%) Execution with Unnecessary Privileges CWE-250 0 (0.0%) Incorrect Check of Function Return Value CWE-253 0 (0.0%) Not Using Password Aging CWE-262 0 (0.0%) Password Aging with Long Expiration CWE-263 0 (0.0%) Incorrect Privilege Assignment CWE-266 0 (0.0%) Privilege Defined With Unsafe Actions CWE-267 0 (0.0%) Privilege Chaining CWE-268 0 (0.0%) Privilege Context Switching Error CWE-270 0 (0.0%) Privilege Dropping / Lowering Errors CWE-271 0 (0.0%) Improper Check for Dropped Privileges CWE-273 0 (0.0%) Unverified Ownership CWE-283 0 (0.0%) Improper Check for Certificate Revocation CWE-299 0 (0.0%) Channel Accessible by Non-Endpoint CWE-300 0 (0.0%) Reflection Attack in an Authentication Protocol CWE-301 0 (0.0%) Missing Critical Step in Authentication CWE-304 0 (0.0%) Missing Authentication for Critical Function CWE-306 0 (0.0%) Improper Restriction of Excessive Authentication Attempts CWE-307 0 (0.0%) Use of Single-factor Authentication CWE-308 0 (0.0%) Cleartext Transmission of Sensitive Information CWE-319 0 (0.0%) Key Exchange without Entity Authentication CWE-322 0 (0.0%) Reusing a Nonce, Key Pair in Encryption CWE-323 0 (0.0%) Missing Cryptographic Step CWE-325 0 (0.0%) Use of a Broken or Risky Cryptographic Algorithm CWE-327 0 (0.0%) Insufficient Entropy CWE-331 0 (0.0%) Small Space of Random Values CWE-334 0 (0.0%) Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) CWE-335 0 (0.0%) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CWE-338 0 (0.0%) Predictable from Observable State CWE-341 0 (0.0%) Use of Less Trusted Source CWE-348 0 (0.0%) Acceptance of Extraneous Untrusted Data With Trusted Data CWE-349 0 (0.0%) Missing Support for Integrity Check CWE-353 0 (0.0%) Signal Handler Race Condition CWE-364 0 (0.0%) Divide By Zero CWE-369 0 (0.0%) Detection of Error Condition Without Action CWE-390 0 (0.0%) Missing Report of Error Condition CWE-392 0 (0.0%) Return of Wrong Status Code CWE-393 0 (0.0%) Insufficient Control of Network Message Volume (Network Amplification) CWE-406 0 (0.0%) Incorrect Behavior Order: Early Amplification CWE-408 0 (0.0%) Unrestricted Upload of File with Dangerous Type CWE-434 0 (0.0%) User Interface (UI) Misrepresentation of Critical Information CWE-451 0 (0.0%) Insecure Default Variable Initialization CWE-453 0 (0.0%) External Initialization of Trusted Variables or Data Stores CWE-454 0 (0.0%) Non-exit on Failed Initialization CWE-455 0 (0.0%) Missing Initialization of a Variable CWE-456 0 (0.0%) Use of sizeof() on a Pointer Type CWE-467 0 (0.0%) Incorrect Pointer Scaling CWE-468 0 (0.0%) Use of Pointer Subtraction to Determine Size CWE-469 0 (0.0%) Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CWE-470 0 (0.0%) NULL Pointer Dereference CWE-476 0 (0.0%) Missing Default Case in Multiple Condition Expression CWE-478 0 (0.0%) Use of Incorrect Operator CWE-480 0 (0.0%) Incorrect Block Delimitation CWE-483 0 (0.0%) Omitted Break Statement in Switch CWE-484 0 (0.0%) Comparison of Classes by Name CWE-486 0 (0.0%) Private Data Structure Returned From A Public Method CWE-495 0 (0.0%) Public Data Assigned to Private Array-Typed Field CWE-496 0 (0.0%) Cloneable Class Containing Sensitive Information CWE-498 0 (0.0%) Serializable Class Containing Sensitive Data CWE-499 0 (0.0%) Weak Password Requirements CWE-521 0 (0.0%) Insufficiently Protected Credentials CWE-522 0 (0.0%) Suspicious Comment CWE-546 0 (0.0%) Use of Hard-coded, Security-relevant Constants CWE-547 0 (0.0%) Dead Code CWE-561 0 (0.0%) Assignment to Variable without Use CWE-563 0 (0.0%) Unsynchronized Access to Shared Data in a Multithreaded Context CWE-567 0 (0.0%) Assignment of a Fixed Address to a Pointer CWE-587 0 (0.0%) Comparison of Object References Instead of Object Contents CWE-595 0 (0.0%) Client-Side Enforcement of Server-Side Security CWE-602 0 (0.0%) Multiple Binds to the Same Port CWE-605 0 (0.0%) Reachable Assertion CWE-617 0 (0.0%) Variable Extraction Error CWE-621 0 (0.0%) Dynamic Variable Evaluation CWE-627 0 (0.0%) Function Call with Incorrectly Specified Arguments CWE-628 0 (0.0%) External Control of Critical State Data CWE-642 0 (0.0%) Incorrect Use of Privileged APIs CWE-648 0 (0.0%) Improper Locking CWE-667 0 (0.0%) Use of Potentially Dangerous Function CWE-676 0 (0.0%) Incorrect Conversion between Numeric Types CWE-681 0 (0.0%) Execution After Redirect (EAR) CWE-698 0 (0.0%) Incorrect Ownership Assignment CWE-708 0 (0.0%) Incorrect Permission Assignment for Critical Resource CWE-732 0 (0.0%) Missing Custom Error Page CWE-756 0 (0.0%) Release of Invalid Pointer or Reference CWE-763 0 (0.0%) Operator Precedence Logic Error CWE-783 0 (0.0%) Access of Memory Location Before Start of Buffer CWE-786 0 (0.0%) Access of Memory Location After End of Buffer CWE-788 0 (0.0%) Use of Hard-coded Credentials CWE-798 0 (0.0%) Buffer Access with Incorrect Length Value CWE-805 0 (0.0%) Untrusted Pointer Dereference CWE-822 0 (0.0%) Expired Pointer Dereference CWE-825 0 (0.0%) Numeric Range Comparison Without Minimum Check CWE-839 0 (0.0%)

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement CVE-2026-76949 2026-09-17
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover CVE-2026-91039 2026-09-17
Token revocation record built from unverified JWT claims in AshAuthentication CVE-2026-78223 2026-09-17
Log injection via an unescaped password reset identity in AshAuthentication CVE-2026-86522 2026-09-17
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication CVE-2026-82761 2026-09-17
Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in CVE-2026-82760 2026-09-17
safeurl validated address is not bound to the request, allowing DNS rebinding CVE-2026-77972 2026-09-15
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry CVE-2026-81638 2026-09-07
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server CVE-2026-82753 2026-09-07
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS CVE-2026-82728 2026-09-04
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS CVE-2026-82729 2026-09-04
httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
Erlang
pkg:otp/inets
CVE-2026-69664 2026-09-01
A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
Erlang
pkg:otp/erts
CVE-2026-75538 2026-09-01
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Erlang
pkg:otp/inets
CVE-2026-74994 2026-09-01
inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
Erlang
pkg:otp/inets
CVE-2026-74835 2026-09-01
inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
Erlang
pkg:otp/inets
CVE-2026-73812 2026-09-01
inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Erlang
pkg:otp/inets
CVE-2026-73276 2026-09-01
inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
Erlang
pkg:otp/inets
CVE-2026-66357 2026-09-01
httpc memory exhaustion via unbounded response header accumulation
Erlang
pkg:otp/inets
CVE-2026-55951 2026-09-01
httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
CVE-2026-71380 2026-09-01
httpd does not enforce the documented default max_clients connection limit
Erlang
pkg:otp/inets
CVE-2026-70399 2026-09-01
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor CVE-2026-82747 2026-09-01
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records CVE-2026-82749 2026-09-01
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another CVE-2026-82748 2026-09-01
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records CVE-2026-82746 2026-09-01
25 per page · 189 CVEs
Page of 8