VulnSea

Tagged “erlang”

CVEs tagged erlang, newest first.

42 CVEsRSS

CVE-2026-54451High· 8.2
4d ago

Elixir protobuf is a pure Elixir implementation of Google Protobuf

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…

Twilightelixir-protobuf · protobufEPSS 0.30%via NVD
CVE-2026-56812Medium
2w ago

Phoenix: Presence keys colliding with `Object.prototype` members break existence checks

Phoenix: Presence keys colliding with `Object.prototype` members break existence checks

Sunlitphoenix · phoenixEPSS 0.51%via GHSA
CVE-2026-56811High· 7.5
2w ago

Phoenix: Unbounded channel joins per transport enables DoS over few connections

Phoenix: Unbounded channel joins per transport enables DoS over few connections

Twilightphoenix · phoenixEPSS 0.76%via GHSA
CVE-2026-48853Critical
3w ago

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

Midnightgrpc · grpcEPSS 0.57%via GHSA
CVE-2026-48599High
3w ago

gRPC Erlang package's path bindings are overridable by query string and request body

gRPC Erlang package's path bindings are overridable by query string and request body

Twilightgrpc · grpcEPSS 0.27%via GHSA
CVE-2026-48854High
3w ago

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

Twilightgrpc · grpcEPSS 0.34%via GHSA
CVE-2026-53430High
3w ago

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

Twilightgrpc · grpcEPSS 0.35%via GHSA
CVE-2026-49757CriticalPoC
3w ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

Abyssalash_authentication · ash_authenticationEPSS 0.61%via GHSA
CVE-2026-53423Medium
1mo ago

membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

Sunlitmembrane_mp4_plugin · membrane_mp4_pluginEPSS 0.13%via GHSA
CVE-2026-49457Critical· 9.1
1mo ago

erlang_quic is a pure Erlang QUIC implementation

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not valida…

Midnightquic · quicEPSS 0.15%via NVD
CVE-2026-49755High
1mo ago

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Twilightreq · reqEPSS 0.60%via GHSA
CVE-2026-49756Medium
1mo ago

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

Sunlitreq · reqEPSS 0.21%via GHSA
CVE-2026-48596Low
2mo ago

Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`

Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`

Sunlittesla · teslaEPSS 0.24%via GHSA
CVE-2026-48594High
2mo ago

Tesla has decompression bomb on response body

Tesla has decompression bomb on response body

Twilighttesla · teslaEPSS 0.46%via GHSA
CVE-2026-48595High
2mo ago

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

Twilighttesla · teslaEPSS 0.49%via GHSA
CVE-2026-48597High
2mo ago

Tesla vulnerable to atom exhaustion via untrusted URL scheme

Tesla vulnerable to atom exhaustion via untrusted URL scheme

Twilighttesla · teslaEPSS 0.35%via GHSA
CVE-2026-48598LowPoC
2mo ago

Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values

Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values

Twilighttesla · teslaEPSS 0.27%via GHSA
CVE-2026-48861Low
2mo ago

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

Sunlitmint · mintEPSS 0.17%via GHSA
CVE-2026-49753Medium
2mo ago

mint: Content-Length header accepts non-RFC "+" sign prefix

mint: Content-Length header accepts non-RFC "+" sign prefix

Sunlitmint · mintEPSS 0.30%via GHSA
CVE-2026-49754High
2mo ago

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

Twilightmint · mintEPSS 0.38%via GHSA
CVE-2026-48862High
2mo ago

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

Twilightmint · mintEPSS 0.38%via GHSA
CVE-2026-48593Medium
2mo ago

oban_web: Unbounded range expansion in cron describe causes memory exhaustion

oban_web: Unbounded range expansion in cron describe causes memory exhaustion

Sunlitoban_web · oban_webEPSS 0.42%via GHSA
CVE-2026-48592Medium
2mo ago

oban_web missing authorization check on `save-job` event handler

oban_web missing authorization check on `save-job` event handler

Sunlitoban_web · oban_webEPSS 0.50%via GHSA
CVE-2022-31008Medium· 5.5
2mo ago

RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins

RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins

Sunlitrabbit_common · rabbit_commonEPSS 0.34%via GHSA
CVE-2023-46118Medium· 4.9
2mo ago

RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API

RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API

Sunlitrabbit_common · rabbit_commonEPSS 1.1%via GHSA
CVE-2026-47077High
2mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-49454Critical· 9.1
2mo ago

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Midnightrelyra · relyraEPSS 0.23%via GHSA
CVE-2026-47066High
2mo ago

Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry

Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry

Twilighthackney · hackneyEPSS 0.75%via GHSA
CVE-2026-47071High
2mo ago

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

Twilighthackney · hackneyEPSS 0.75%via GHSA
CVE-2026-47076Medium
2mo ago

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

Sunlithackney · hackneyEPSS 0.23%via GHSA
CVEs tagged “erlang” · VulnSea