Analysis
Common Weaknesses
The most common CWE weakness classes across Erlang ecosystem CVEs
The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.
Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.
Violation of Secure Design Principles CWE-657 CWE-657 at MITRE
The product violates well-established principles for secure design.
Improper Isolation or Compartmentalization CWE-653
1
(100.0%)
Execution with Unnecessary Privileges CWE-250
0
(0.0%)
Not Failing Securely ('Failing Open') CWE-636
0
(0.0%)
Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism') CWE-637
0
(0.0%)
Not Using Complete Mediation CWE-638
0
(0.0%)
Reliance on a Single Factor in a Security Decision CWE-654
0
(0.0%)
Insufficient Psychological Acceptability CWE-655
0
(0.0%)
Reliance on Security Through Obscurity CWE-656
0
(0.0%)
Lack of Administrator Control over Security CWE-671
0
(0.0%)
Improper Identifier for IP Block used in System-On-Chip (SOC) CWE-1192
0
(0.0%)
Dependency on Vulnerable Third-Party Component CWE-1395
0
(0.0%)
CVEs
CVEs for Violation of Secure Design Principles CWE-657
| Summary | Publication | CVE ID | Published |
|---|---|---|---|
| Boruta dynamic client registration allows creation of over-privileged OAuth clients | CVE-2026-65635 | 2026-07-30 |
1 CVE