Resource Limitation Vulnerability in Ueberauth Guardian's Permissions Module
CVE-2026-55734

6.9MEDIUM

Key Information:

Vendor

Ueberauth

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-55734?

The Ueberauth Guardian's Permissions module contains a vulnerability that allows for Denial of Service through the exhaustion of the BEAM atom table. The library improperly handles permission keys by converting them to atoms without appropriate validation. This can lead to an attacker crafting malicious key-value pairs that cause an increase in unique atoms, overwhelming the atom table and potentially causing the BEAM node to crash. Attackers can exploit this when they have control over the permissions map passed to the encode_permissions!/1 function, ultimately leading to a denial of service for the application.

Affected Version(s)

guardian 2.0.0 < 2.4.1

guardian b7a6128ca4d0ffb7f7df5219dd982304ff9d6802 < 8d4efbfc352d30f5fcfc75a4d69a795b0e472724

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Yordis Prieto
Jonatan Männchen / EEF
.