The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Improper Following of Specification by Caller CWE-573 CWE-573 at MITRE

The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.

Improper Following of a Certificate's Chain of Trust: 1 CVEs (100.0%) — click to drill down Struts: Incomplete validate() Method Definition: 0 CVEs (0.0%) — click to drill down Struts: Form Bean Does Not Extend Validation Class: 0 CVEs (0.0%) — click to drill down Creation of chroot Jail Without Changing Working Directory: 0 CVEs (0.0%) — click to drill down Incorrect Check of Function Return Value: 0 CVEs (0.0%) — click to drill down Missing Critical Step in Authentication: 0 CVEs (0.0%) — click to drill down Missing Cryptographic Step: 0 CVEs (0.0%) — click to drill down Generation of Predictable IV with CBC Mode: 0 CVEs (0.0%) — click to drill down Improperly Implemented Security Check for Standard: 0 CVEs (0.0%) — click to drill down Undefined Behavior for Input to API: 0 CVEs (0.0%) — click to drill down finalize() Method Without super.finalize(): 0 CVEs (0.0%) — click to drill down EJB Bad Practices: Use of Sockets: 0 CVEs (0.0%) — click to drill down EJB Bad Practices: Use of Class Loader: 0 CVEs (0.0%) — click to drill down J2EE Bad Practices: Non-serializable Object Stored in Session: 0 CVEs (0.0%) — click to drill down clone() Method Without super.clone(): 0 CVEs (0.0%) — click to drill down Object Model Violation: Just One of Equals and Hashcode Defined: 0 CVEs (0.0%) — click to drill down Function Call with Incorrectly Specified Arguments: 0 CVEs (0.0%) — click to drill down Multiple Operations on Resource in Single-Operation Context: 0 CVEs (0.0%) — click to drill down Use of Multiple Resources with Duplicate Identifier: 0 CVEs (0.0%) — click to drill down Use of Low-Level Functionality: 0 CVEs (0.0%) — click to drill down Total 1

CVEs

CVEs for Improper Following of Specification by Caller CWE-573

Summary Publication CVE ID Published
Non-CA certificate accepted as intermediate issuer in public_key path validation
pkg:otp/public_key
CVE-2026-42789 2026-05-27
1 CVE