Denial of Service Vulnerability in ueberauth Guardian Product by Ueberauth
CVE-2026-54894

6.9MEDIUM

Key Information:

Vendor

Ueberauth

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-54894?

The ueberauth Guardian product is susceptible to a denial of service attack due to improper resource allocation. An attacker can exploit this vulnerability by sending specially crafted binary input, resulting in unbounded atom creation. Each unique input generates a new atom, filling the fixed atom table in the BEAM virtual machine. This can lead to a situation where the atom table reaches its limit, causing the application to crash and affecting all systems running on the same BEAM node. This vulnerability underscores the importance of implementing throttling and sanitation mechanisms to mitigate the risks associated with arbitrary binary inputs.

Affected Version(s)

guardian 0.1.0 < 2.4.1

guardian 7126fa433afc2563fcac0c9aa35193965f8fd5f8 < 2952657e42e6341a67e6aaad09d8f0b40ae917cb

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Yordis Prieto
Jonatan Männchen / EEF
.