Tagged “erlang”
CVEs tagged erlang, newest first.
42 CVEsRSS
CVE-2026-54451High· 8.2Elixir protobuf is a pure Elixir implementation of Google Protobuf
Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…
CVE-2026-56812MediumPhoenix: Presence keys colliding with `Object.prototype` members break existence checks
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
CVE-2026-56811High· 7.5Phoenix: Unbounded channel joins per transport enables DoS over few connections
Phoenix: Unbounded channel joins per transport enables DoS over few connections
CVE-2026-48853CriticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
CVE-2026-48599HighgRPC Erlang package's path bindings are overridable by query string and request body
gRPC Erlang package's path bindings are overridable by query string and request body
CVE-2026-48854HighgRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
CVE-2026-49757CriticalPoCAshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
CVE-2026-53423Mediummembrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
CVE-2026-49457Critical· 9.1erlang_quic is a pure Erlang QUIC implementation
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not valida…
CVE-2026-49755HighReq vulnerable to unbounded archive/compression extraction triggered by response content-type
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
CVE-2026-49756MediumReq vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
CVE-2026-48596LowTesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
CVE-2026-48594HighTesla has decompression bomb on response body
Tesla has decompression bomb on response body
CVE-2026-48595HighTesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
CVE-2026-48597HighTesla vulnerable to atom exhaustion via untrusted URL scheme
Tesla vulnerable to atom exhaustion via untrusted URL scheme
CVE-2026-48598LowPoCTesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
CVE-2026-48861Lowmint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
CVE-2026-49753Mediummint: Content-Length header accepts non-RFC "+" sign prefix
mint: Content-Length header accepts non-RFC "+" sign prefix
CVE-2026-49754Highmint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
CVE-2026-48862Highmint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
CVE-2026-48593Mediumoban_web: Unbounded range expansion in cron describe causes memory exhaustion
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
CVE-2026-48592Mediumoban_web missing authorization check on `save-job` event handler
oban_web missing authorization check on `save-job` event handler
CVE-2022-31008Medium· 5.5RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
CVE-2023-46118Medium· 4.9RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
CVE-2026-47077HighHackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
CVE-2026-49454Critical· 9.1Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVE-2026-47066HighHackney has an infinite loop on non-token byte at start of an Alt-Svc entry
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
CVE-2026-47071HighHackney: `ssl:connect/2` post-handshake upgrade has no timeout
Hackney: `ssl:connect/2` post-handshake upgrade has no timeout
CVE-2026-47076MediumHackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host