CNA
  • CVEs
  • Weaknesses
    • Scope
    • CVE Criteria
    • Security Policy
    • Maintainer Process
    • Coordinator Process
    • Data Licensing
    • API Access
    • Contact
  • CVEs
  • Weaknesses
  • Documentation
  • Scope
  • CVE Criteria
  • Security Policy
  • Maintainer Process
  • Coordinator Process
  • Data Licensing
  • API Access
  • Contact

Documentation

Scope Definition

Which projects and packages the EEF CNA covers

A CVE Numbering Authority (CNA) can only assign CVE identifiers for products within its scope. This page defines which projects our CNA covers.

Our CNA assigns CVE IDs for:

Vulnerabilities in active packages hosted on Hex.pm, and in active projects hosted under the GitHub organizations @elixir-lang, @erlang, @erlef-cna, @erlef, @gleam-lang, @hexpm, @nerves-hub, @nerves-project, and @OpenRiak unless covered by the scope of another CNA.

CNA

The Erlang Ecosystem Foundation's CVE Numbering Authority for the BEAM ecosystem.

Records

  • All CVEs
  • Common Weaknesses
  • CVE index (JSON)
  • OSV feed (JSON)

Process

  • Scope
  • CVE Criteria
  • Maintainer Process
  • Coordinator Process

More

  • Report a Vulnerability
  • Contact
  • Security Policy
  • Data Licensing
  • erlef.org
© 2026 Erlang Ecosystem Foundation. CVE data licensed CC-BY 4.0.