CNA
  • CVEs
  • Weaknesses
    • Scope
    • CVE Criteria
    • Security Policy
    • Maintainer Process
    • Coordinator Process
    • Varsel Guide
    • Data Licensing
    • API Access
    • Contact
  • CVEs
  • Weaknesses
  • Documentation
  • Scope
  • CVE Criteria
  • Security Policy
  • Maintainer Process
  • Coordinator Process
  • Varsel Guide
  • Data Licensing
  • API Access
  • Contact

EEF CNA

Issued CVEs

Vulnerabilities assigned and published by the EEF CNA.

Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2025-48043 Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
Hex / ash
GitHub / ash-project/ash
H 8.6 2025-10-10
CVE-2025-48041 SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
Erlang / ssh
GitHub / erlang/otp
H 7.1 2025-09-11
CVE-2025-48040 Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
Erlang / ssh
GitHub / erlang/otp
M 6.9 2025-09-11
CVE-2025-48039 Unverified Paths can Cause Excessive Use of System Resources
Erlang / ssh
GitHub / erlang/otp
M 5.3 2025-09-11
CVE-2025-48038 Unverified File Handles can Cause Excessive Use of System Resources
Erlang / ssh
GitHub / erlang/otp
M 5.3 2025-09-11
CVE-2025-48042 Before action hooks may execute in certain scenarios despite a request being forbidden
Hex / ash
GitHub / ash-project/ash
H 7.1 2025-09-07
CVE-2025-4754 Missing Session Revocation on Logout in ash_authentication_phoenix
Hex / ash_authentication_phoenix
GitHub / team-alembic/ash_authentication_phoenix
L 2.3 2025-06-17
CVE-2025-4748 Absolute path traversal in zip:unzip/1,2
Erlang / stdlib
GitHub / erlang/otp
M 4.8 2025-06-16
25 per page · 183 CVEs
« Page of 8
CNA

The Erlang Ecosystem Foundation's CVE Numbering Authority for the BEAM ecosystem.

Records

  • All CVEs
  • Common Weaknesses
  • CVE index (JSON)
  • OSV feed (JSON)

Process

  • Scope
  • CVE Criteria
  • Maintainer Process
  • Coordinator Process
  • Varsel Guide

More

  • Report a Vulnerability
  • Contact
  • Security Policy
  • Data Licensing
  • erlef.org
© 2026 Erlang Ecosystem Foundation. CVE data licensed CC-BY 4.0.

We can't find the internet

Attempting to reconnect

Something went wrong!

Attempting to reconnect