Erlang Ecosystem Foundation
First CVE: Jun 16, 2025Active for: 1 year
131
CVEs Published
More CVEs Published than 74% of tracked CNAs
65.5
Avg CVEs / Year
More Avg CVEs / Year than 86% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Erlang Ecosystem Foundation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2025
13 months ago
Most Recent CVE
Jul 17, 2026
7 days ago
Top CVEs
All CVEs published by Erlang Ecosystem Foundation as a CNA, regardless of affected vendor or product.
131 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55954CRITICAL Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims.
The Ueberauth.Strategy.Apple.Token.payload/2 | Jul 14, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-58229HIGH Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service.
The Mint.H | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-53426HIGH Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation.
MDEx.parse_document/2 accepts a {:json, json} source. In lib/mdex | Jun 29, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-59252HIGH Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitima | Jul 17, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-59694HIGH Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, deg | Jul 17, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-59695HIGH Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily | Jul 17, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-56810HIGH Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversized chunked transfer-encoded resp | Jul 6, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-58226HIGH Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding.
hpax decodes HPACK variable-len | Jul 6, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-55952HIGH The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passi | Jul 2, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-54892HIGH Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn. | Jun 23, 2026 | 8.7 | 35 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA131 CVEs
11%
40%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local25 (19.1%)
Network106 (80.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low120 (91.6%)
High11 (8.4%)
Unknown0 (0.0%)
User Interaction
None115 (87.8%)
Unknown0 (0.0%)
Required5 (3.8%)
Privileges Required
Low24 (18.3%)
High0 (0.0%)
None107 (81.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (131 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Erlang Ecosystem Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Erlang Ecosystem Foundation as a CNA — matched by CVE ID, not by organization name.