Vendor Intelligence

erlang

5 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-32687 · CVSS 7.5

Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3`

View CVE report →
CVE-2026-32689 · CVSS 7.5

Phoenix: Long-poll NDJSON body splitting causes large memory allocation

View CVE report →
CVE-2026-42793 · CVSS 7.5

Absinthe: Unbounded atom creation from parsed directive name

View CVE report →
CVE-2026-43967 · CVSS 7.5

Absinthe: Quadratic fragment-name uniqueness check

View CVE report →
CVE-2026-8469 · CVSS 7.5

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

View CVE report →