Denial of Service Vulnerability in ueberauth Guardian Product by Ueberauth
CVE-2026-54894
What is CVE-2026-54894?
The ueberauth Guardian product is susceptible to a denial of service attack due to improper resource allocation. An attacker can exploit this vulnerability by sending specially crafted binary input, resulting in unbounded atom creation. Each unique input generates a new atom, filling the fixed atom table in the BEAM virtual machine. This can lead to a situation where the atom table reaches its limit, causing the application to crash and affecting all systems running on the same BEAM node. This vulnerability underscores the importance of implementing throttling and sanitation mechanisms to mitigate the risks associated with arbitrary binary inputs.
Affected Version(s)
guardian 0.1.0 < 2.4.1
guardian 7126fa433afc2563fcac0c9aa35193965f8fd5f8 < 2952657e42e6341a67e6aaad09d8f0b40ae917cb
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
