The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1000 CWE-1000 at MITRE

We're looking at the CWE hierarchy through the Research Concepts view.

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Boruta accepts expired JWT client assertions due to missing exp claim validation CVE-2026-53431 2026-07-30
Boruta dynamic client registration allows creation of over-privileged OAuth clients CVE-2026-65635 2026-07-30
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching CVE-2026-54885 2026-07-30
Insufficient verification of Hex package metadata in Gleam
pkg:sid/gleam.run/gleam
pkg:oci/gleam
CVE-2026-59247 2026-07-29
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion CVE-2026-65624 2026-07-28
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS CVE-2026-59248 2026-07-28
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
pkg:otp/erts
CVE-2026-54890 2026-07-27
Denial of service via exponential certificate policy tree growth in path validation
pkg:otp/public_key
CVE-2026-59251 2026-07-27
Megaco flex scanner buffer overflow via oversized property parm name
pkg:otp/megaco
CVE-2026-59250 2026-07-27
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
pkg:otp/ssl
CVE-2026-55953 2026-07-27
Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
pkg:otp/erts
CVE-2026-55737 2026-07-27
Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
pkg:otp/stdlib
CVE-2026-47078 2026-07-27
epmd permanent DoS via EMFILE on accept(2) in erts
pkg:otp/erts
CVE-2026-42792 2026-07-27
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
pkg:otp/ssl
CVE-2026-58227 2026-07-27
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit CVE-2026-65623 2026-07-24
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain CVE-2026-59252 2026-07-17
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment CVE-2026-59694 2026-07-17
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain CVE-2026-59695 2026-07-17
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections CVE-2026-59249 2026-07-16
Missing ID token claim validation in ueberauth_apple allows account takeover CVE-2026-55954 2026-07-14
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory CVE-2026-59246 2026-07-14
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS CVE-2026-58229 2026-07-14
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> CVE-2026-58228 2026-07-13
Cookie attribute injection in Plug.Conn.Cookies.encode/2 CVE-2026-56813 2026-07-10
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) CVE-2026-56814 2026-07-10
25 per page · 146 CVEs
Page of 6