The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Exposure of Resource to Wrong Sphere CWE-668 CWE-668 at MITRE

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Exposure of Sensitive Information to an Unauthorized Actor: 3 CVEs (100.0%) — click to drill down J2EE Misconfiguration: Entity Bean Declared Remote: 0 CVEs (0.0%) — click to drill down Use of Externally-Controlled Format String: 0 CVEs (0.0%) — click to drill down Passing Mutable Objects to an Untrusted Method: 0 CVEs (0.0%) — click to drill down Returning a Mutable Object to an Untrusted Caller: 0 CVEs (0.0%) — click to drill down Insecure Temporary File: 0 CVEs (0.0%) — click to drill down Transmission of Private Resources into a New Sphere ('Resource Leak'): 0 CVEs (0.0%) — click to drill down Uncontrolled Search Path Element: 0 CVEs (0.0%) — click to drill down Unquoted Search Path or Element: 0 CVEs (0.0%) — click to drill down Exposure of Data Element to Wrong Session: 0 CVEs (0.0%) — click to drill down Public cloneable() Method Without Final ('Object Hijack'): 0 CVEs (0.0%) — click to drill down Use of Inner Class Containing Sensitive Data: 0 CVEs (0.0%) — click to drill down Critical Public Variable Without Final Modifier: 0 CVEs (0.0%) — click to drill down Cloneable Class Containing Sensitive Information: 0 CVEs (0.0%) — click to drill down Serializable Class Containing Sensitive Data: 0 CVEs (0.0%) — click to drill down Insufficiently Protected Credentials: 0 CVEs (0.0%) — click to drill down Use of Cache Containing Sensitive Information: 0 CVEs (0.0%) — click to drill down Files or Directories Accessible to External Parties: 0 CVEs (0.0%) — click to drill down Array Declared Public, Final, and Static: 0 CVEs (0.0%) — click to drill down finalize() Method Declared Public: 0 CVEs (0.0%) — click to drill down Struts: Non-private Field in ActionForm Class: 0 CVEs (0.0%) — click to drill down External Control of Critical State Data: 0 CVEs (0.0%) — click to drill down Incorrect Permission Assignment for Critical Resource: 0 CVEs (0.0%) — click to drill down Access to Critical Private Variable via Public Method: 0 CVEs (0.0%) — click to drill down Use of Implicit Intent for Sensitive Communication: 0 CVEs (0.0%) — click to drill down Improper Isolation of Shared Resources on System-on-a-Chip (SoC): 0 CVEs (0.0%) — click to drill down Assumed-Immutable Data is Stored in Writable Memory: 0 CVEs (0.0%) — click to drill down Binding to an Unrestricted IP Address: 0 CVEs (0.0%) — click to drill down Improper Isolation of Shared Resources in Network On Chip (NoC): 0 CVEs (0.0%) — click to drill down Total 4
Exposure of Sensitive Information to an Unauthorized Actor CWE-200 3 (100.0%) J2EE Misconfiguration: Entity Bean Declared Remote CWE-8 0 (0.0%) Use of Externally-Controlled Format String CWE-134 0 (0.0%) Passing Mutable Objects to an Untrusted Method CWE-374 0 (0.0%) Returning a Mutable Object to an Untrusted Caller CWE-375 0 (0.0%) Insecure Temporary File CWE-377 0 (0.0%) Transmission of Private Resources into a New Sphere ('Resource Leak') CWE-402 0 (0.0%) Uncontrolled Search Path Element CWE-427 0 (0.0%) Unquoted Search Path or Element CWE-428 0 (0.0%) Exposure of Data Element to Wrong Session CWE-488 0 (0.0%) Public cloneable() Method Without Final ('Object Hijack') CWE-491 0 (0.0%) Use of Inner Class Containing Sensitive Data CWE-492 0 (0.0%) Critical Public Variable Without Final Modifier CWE-493 0 (0.0%) Cloneable Class Containing Sensitive Information CWE-498 0 (0.0%) Serializable Class Containing Sensitive Data CWE-499 0 (0.0%) Insufficiently Protected Credentials CWE-522 0 (0.0%) Use of Cache Containing Sensitive Information CWE-524 0 (0.0%) Files or Directories Accessible to External Parties CWE-552 0 (0.0%) Array Declared Public, Final, and Static CWE-582 0 (0.0%) finalize() Method Declared Public CWE-583 0 (0.0%) Struts: Non-private Field in ActionForm Class CWE-608 0 (0.0%) External Control of Critical State Data CWE-642 0 (0.0%) Incorrect Permission Assignment for Critical Resource CWE-732 0 (0.0%) Access to Critical Private Variable via Public Method CWE-767 0 (0.0%) Use of Implicit Intent for Sensitive Communication CWE-927 0 (0.0%) Improper Isolation of Shared Resources on System-on-a-Chip (SoC) CWE-1189 0 (0.0%) Assumed-Immutable Data is Stored in Writable Memory CWE-1282 0 (0.0%) Binding to an Unrestricted IP Address CWE-1327 0 (0.0%) Improper Isolation of Shared Resources in Network On Chip (NoC) CWE-1331 0 (0.0%)

CVEs

CVEs for Exposure of Resource to Wrong Sphere CWE-668

Summary Publication CVE ID Published
SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root
pkg:otp/ssh
CVE-2026-53422 2026-07-02
SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured
pkg:otp/ssh
CVE-2026-48855 2026-06-10
SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration
pkg:otp/ssh
CVE-2026-48859 2026-06-10
Improper authorization in device bulk actions and device update API allows cross-organization device control
pkg:otp/nerves_hub
pkg:oci/nerves-hub
CVE-2026-28806 2026-03-10
4 CVEs