Erlang Ecosystem Foundation
CVE Numbering Authority for the BEAM ecosystem
A collaborative effort to assign and maintain CVE identifiers within the Erlang, Elixir, and Gleam ecosystem — a consistent, transparent process for reporting, documenting, and mitigating security vulnerabilities.
As a CNA (CVE Numbering Authority), we assign CVE IDs for vulnerabilities in active packages hosted on Hex.pm and in projects under the GitHub organizations listed in our scope. All CVEs are also published to OSV.dev. This CNA is hosted by the Erlang Ecosystem Foundation's Security Working Group.
Activity
CVE publications by quarter
Latest
Recently published
Boruta accepts expired JWT client assertions due to missing exp claim validation
Boruta dynamic client registration allows creation of over-privileged OAuth clients
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
Resources
Learn more
CNA Scope
What projects we cover
Contact
Report a vulnerability
CVE Criteria
Assignment guidelines
Security Policy
Disclosure process
Common Weaknesses
CWE distribution
Maintainer Process
Coordinated disclosure guide
Coordinator Process
For CNA volunteers
Data Licensing
CC-BY 4.0 terms
All CVEs
Browse published records