🔐 CVE Alert

CVE-2026-55733

UNKNOWN 0.0

Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check. The perm_set argument (the application's small, finite set of legitimate permission names) is discarded, so any external string flows straight into atom creation. This encoder is selected with use Guardian.Permissions, encoding: Guardian.Permissions.AtomEncoding and reached through the imported encode/3 entry point. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that funnels attacker-influenced permission scopes (from a request body, a JWT claim, or other external input) into encode/3 therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node with system_limit, taking down every application running on it. The default encoder is Guardian.Permissions.BitwiseEncoding, which is not affected. This issue affects guardian: from 2.0.0 before 2.4.1.

CWE CWE-770
Vendor ueberauth
Product guardian
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for ueberauth guardian

Be the first to know when new unknown vulnerabilities affecting ueberauth guardian are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ueberauth / guardian
2.0.0 < 2.4.1
ueberauth / guardian
b7a6128ca4d0ffb7f7df5219dd982304ff9d6802 < 9cd268557846aa4c3ad53566c08f2c190ee5513f

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ueberauth/guardian/security/advisories/GHSA-fjr5-7xrc-hmpj cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-55733.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-55733 github.com: https://github.com/ueberauth/guardian/commit/9cd268557846aa4c3ad53566c08f2c190ee5513f

Credits

Peter Ullrich Yordis Prieto Jonatan Männchen / EEF