Resource Limitation Vulnerability in Ueberauth Guardian's Permissions Module
CVE-2026-55734
What is CVE-2026-55734?
The Ueberauth Guardian's Permissions module contains a vulnerability that allows for Denial of Service through the exhaustion of the BEAM atom table. The library improperly handles permission keys by converting them to atoms without appropriate validation. This can lead to an attacker crafting malicious key-value pairs that cause an increase in unique atoms, overwhelming the atom table and potentially causing the BEAM node to crash. Attackers can exploit this when they have control over the permissions map passed to the encode_permissions!/1 function, ultimately leading to a denial of service for the application.
Affected Version(s)
guardian 2.0.0 < 2.4.1
guardian b7a6128ca4d0ffb7f7df5219dd982304ff9d6802 < 8d4efbfc352d30f5fcfc75a4d69a795b0e472724
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
