The chart below shows the most common weaknesses found in vulnerabilities across the Erlang ecosystem. Understanding which weakness types recur most often helps library authors and application developers focus their security efforts where they matter most.

Each CVE is mapped to its CWE (Common Weakness Enumeration) using the MITRE CWE hierarchy. A slice's count includes every CVE reachable anywhere below it in the hierarchy, not just CVEs assigned that exact CWE — click a slice or legend row to drill into its direct children and see the same breakdown one level down.

Viewing · CWE-1003 CWE-1003 at MITRE

We're looking at the CWE hierarchy through the Weaknesses for Simplified Mapping of Published Vulnerabilities view.

Uncontrolled Resource Consumption: 43 CVEs (34.7%) — click to drill down Use of Incorrectly-Resolved Name or Reference: 10 CVEs (8.1%) — click to drill down Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'): 8 CVEs (6.5%) — click to drill down Improper Authentication: 8 CVEs (6.5%) — click to drill down Incorrect Authorization: 8 CVEs (6.5%) — click to drill down Externally Controlled Reference to a Resource in Another Sphere: 6 CVEs (4.8%) — click to drill down Improper Input Validation: 5 CVEs (4.0%) — click to drill down Interpretation Conflict: 5 CVEs (4.0%) — click to drill down Insufficient Verification of Data Authenticity: 4 CVEs (3.2%) — click to drill down Inefficient Algorithmic Complexity: 4 CVEs (3.2%) — click to drill down Operation on a Resource after Expiration or Release: 3 CVEs (2.4%) — click to drill down Excessive Iteration: 3 CVEs (2.4%) — click to drill down Improper Encoding or Escaping of Output: 2 CVEs (1.6%) — click to drill down Improper Restriction of Operations within the Bounds of a Memory Buffer: 2 CVEs (1.6%) — click to drill down Uncontrolled Recursion: 2 CVEs (1.6%) — click to drill down Improper Control of Dynamically-Managed Code Resources: 2 CVEs (1.6%) — click to drill down Exposure of Sensitive Information to an Unauthorized Actor: 1 CVEs (0.8%) — click to drill down Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'): 1 CVEs (0.8%) — click to drill down Improper Resource Shutdown or Release: 1 CVEs (0.8%) — click to drill down Exposure of Resource to Wrong Sphere: 1 CVEs (0.8%) — click to drill down Incorrect Resource Transfer Between Spheres: 1 CVEs (0.8%) — click to drill down Incorrect Calculation: 1 CVEs (0.8%) — click to drill down Improper Check for Unusual or Exceptional Conditions: 1 CVEs (0.8%) — click to drill down Improper Handling of Exceptional Conditions: 1 CVEs (0.8%) — click to drill down Missing Authorization: 1 CVEs (0.8%) — click to drill down Improper Privilege Management: 0 CVEs (0.0%) — click to drill down Missing Encryption of Sensitive Data: 0 CVEs (0.0%) — click to drill down Inadequate Encryption Strength: 0 CVEs (0.0%) — click to drill down Use of a Broken or Risky Cryptographic Algorithm: 0 CVEs (0.0%) — click to drill down Use of Insufficiently Random Values: 0 CVEs (0.0%) — click to drill down Improper Synchronization: 0 CVEs (0.0%) — click to drill down Improper Initialization: 0 CVEs (0.0%) — click to drill down Always-Incorrect Control Flow Implementation: 0 CVEs (0.0%) — click to drill down Incorrect Comparison: 0 CVEs (0.0%) — click to drill down Incorrect Type Conversion or Cast: 0 CVEs (0.0%) — click to drill down Incorrect Permission Assignment for Critical Resource: 0 CVEs (0.0%) — click to drill down Insecure Storage of Sensitive Information: 0 CVEs (0.0%) — click to drill down Total 116
Uncontrolled Resource Consumption CWE-400 43 (34.7%) Use of Incorrectly-Resolved Name or Reference CWE-706 10 (8.1%) Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-74 8 (6.5%) Improper Authentication CWE-287 8 (6.5%) Incorrect Authorization CWE-863 8 (6.5%) Externally Controlled Reference to a Resource in Another Sphere CWE-610 6 (4.8%) Improper Input Validation CWE-20 5 (4.0%) Interpretation Conflict CWE-436 5 (4.0%) Insufficient Verification of Data Authenticity CWE-345 4 (3.2%) Inefficient Algorithmic Complexity CWE-407 4 (3.2%) Operation on a Resource after Expiration or Release CWE-672 3 (2.4%) Excessive Iteration CWE-834 3 (2.4%) Improper Encoding or Escaping of Output CWE-116 2 (1.6%) Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-119 2 (1.6%) Uncontrolled Recursion CWE-674 2 (1.6%) Improper Control of Dynamically-Managed Code Resources CWE-913 2 (1.6%) Exposure of Sensitive Information to an Unauthorized Actor CWE-200 1 (0.8%) Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-362 1 (0.8%) Improper Resource Shutdown or Release CWE-404 1 (0.8%) Exposure of Resource to Wrong Sphere CWE-668 1 (0.8%) Incorrect Resource Transfer Between Spheres CWE-669 1 (0.8%) Incorrect Calculation CWE-682 1 (0.8%) Improper Check for Unusual or Exceptional Conditions CWE-754 1 (0.8%) Improper Handling of Exceptional Conditions CWE-755 1 (0.8%) Missing Authorization CWE-862 1 (0.8%) Improper Privilege Management CWE-269 0 (0.0%) Missing Encryption of Sensitive Data CWE-311 0 (0.0%) Inadequate Encryption Strength CWE-326 0 (0.0%) Use of a Broken or Risky Cryptographic Algorithm CWE-327 0 (0.0%) Use of Insufficiently Random Values CWE-330 0 (0.0%) Improper Synchronization CWE-662 0 (0.0%) Improper Initialization CWE-665 0 (0.0%) Always-Incorrect Control Flow Implementation CWE-670 0 (0.0%) Incorrect Comparison CWE-697 0 (0.0%) Incorrect Type Conversion or Cast CWE-704 0 (0.0%) Incorrect Permission Assignment for Critical Resource CWE-732 0 (0.0%) Insecure Storage of Sensitive Information CWE-922 0 (0.0%)

CVEs

Every CVE in this view

Summary Publication CVE ID Published
Boruta accepts expired JWT client assertions due to missing exp claim validation CVE-2026-53431 2026-07-30
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching CVE-2026-54885 2026-07-30
Insufficient verification of Hex package metadata in Gleam
pkg:sid/gleam.run/gleam
pkg:oci/gleam
CVE-2026-59247 2026-07-29
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion CVE-2026-65624 2026-07-28
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS CVE-2026-59248 2026-07-28
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
pkg:otp/erts
CVE-2026-54890 2026-07-27
Denial of service via exponential certificate policy tree growth in path validation
pkg:otp/public_key
CVE-2026-59251 2026-07-27
Megaco flex scanner buffer overflow via oversized property parm name
pkg:otp/megaco
CVE-2026-59250 2026-07-27
Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
pkg:otp/erts
CVE-2026-55737 2026-07-27
epmd permanent DoS via EMFILE on accept(2) in erts
pkg:otp/erts
CVE-2026-42792 2026-07-27
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
pkg:otp/ssl
CVE-2026-58227 2026-07-27
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit CVE-2026-65623 2026-07-24
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain CVE-2026-59252 2026-07-17
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment CVE-2026-59694 2026-07-17
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain CVE-2026-59695 2026-07-17
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections CVE-2026-59249 2026-07-16
Missing ID token claim validation in ueberauth_apple allows account takeover CVE-2026-55954 2026-07-14
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory CVE-2026-59246 2026-07-14
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS CVE-2026-58229 2026-07-14
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> CVE-2026-58228 2026-07-13
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) CVE-2026-56814 2026-07-10
SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service CVE-2026-58225 2026-07-10
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff CVE-2026-56812 2026-07-07
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service CVE-2026-56811 2026-07-07
Email-derived URL path injection in the Swoosh Microsoft Graph adapter CVE-2026-54893 2026-07-06
25 per page · 116 CVEs
Page of 5