- CVE-2026-47073 — Unbounded memory consumption in WebSocket client
- CVE-2026-47067 — Atom table exhaustion via unrecognized URL schemes
- CVE-2026-47072 — CRLF injection in WebSocket upgrade request
- CVE-2026-47076 — SSRF allowlist bypass via percent-encoded host
- CVE-2026-47077 — Unbounded body accumulation in HTTP/3 response loop
- CVE-2026-47070 — HTTP/3 redirect leaks Authorization/Cookie headers cross-origin
- CVE-2026-47075 — CRLF injection in request target/query parameters
- CVE-2026-47071 — SOCKS5 TLS upgrade ignores caller timeout
- CVE-2026-47066 — Infinite loop in Alt-Svc response parser
- CVE-2026-47069 — CRLF injection in cookie domain/path options
- CVE-2026-47068 — Cross-session PubSub topic injection
- CVE-2026-8467 — Unauthenticated RCE via HEEx template injection
- CVE-2026-8469 — Atom table exhaustion DoS
- CVE-2026-8468 / GHSA-468c-vq7p-gh64 — Multipart header parsing memory DoS
- CVE-2026-43970 — SPDY inflate decompression bomb
- CVE-2026-8466 — Multipart header parsing memory DoS
- CVE-2026-39806 — HTTP/1 chunked decoder infinite loop
- CVE-2026-39803 — Chunked body reader ignores length cap
- CVE-2026-32687 — SQL injection in notifications channel names
- CVE-2026-43968 — SSE CR injection
- CVE-2026-7790 — Chunk-size parsing CPU/memory DoS
- CVE-2026-43969 — Cookie request header injection
- CVE-2026-42793 — Atom table exhaustion via GraphQL SDL names
- CVE-2026-43967 — Quadratic fragment-name DoS
- CVE-2026-42794 — GraphiQL reflected XSS
- CVE-2026-44700 / GHSA-qwfw-ggxw-577c — DTLS peer fingerprint validation gap
- CVE-2026-32686 / GHSA-rhv4-8758-jx7v — Unbounded exponent DoS
- CVE-2026-32689 / GHSA-628h-q48j-jr6q — Long-poll NDJSON memory DoS
- CVE-2026-39805 — Duplicate Content-Length request smuggling
- CVE-2026-39804 — WebSocket deflate output-size DoS
- CVE-2026-39807 — Trusted client-supplied URI scheme
- CVE-2026-42786 — WebSocket fragmented message memory DoS
- CVE-2026-42788 — HTTP/2 frame-size check after buffering
- CVE-2026-32148 — Lockfile checksum integrity bypass
- CVE-2026-32688 / GHSA-q8x4-x7mp-5vg2 — HTTP/2 :scheme atom-table exhaustion
- CVE-2026-32147 — SFTP chroot bypass
- CVE-2026-32146 — Git dependency path validation flaw
- CVE-2026-28808 — CGI auth bypass
- CVE-2026-32144 — OCSP authorization bypass
- CVE-2026-28810 — Predictable DNS transaction IDs
- CVE-2026-32145 — Multipart body size-limit bypass
- CVE-2026-34593 / GHSA-jjf9-w5vj-r6vp — Module atom exhaustion DoS
- CVE-2026-34715 / GHSA-x2w3-23jr-hrpf — CRLF response splitting
- CVE-2026-33872 / GHSA-rwcr-rpcc-3g9m — Worker protocol race data leakage
- CVE-2026-28809 — XXE local file read / potential SSRF
- CVE-2026-23940 — Oversized package upload DoS
- CVE-2026-21622 — Password reset tokens do not expire
- CVE-2026-21621 — OAuth scope enforcement flaw
- CVE-2026-23939 — Local file store path traversal
- CVE-2026-21618 — OAuth device authorization XSS
- CVE-2026-21619 — Unsafe Erlang term deserialization
- CVE-2026-21620 — TFTP path traversal
- CVE-2026-23942 — SFTP root escape via component-agnostic prefix validation
- ERLEF CNA CVE Index
- GitHub Advisory Database — Erlang Ecosystem
- OSV Database
- Linked vendor advisories