Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-55733— Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation

Quick assessment

Affected
ueberauth guardian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ueberauth Guardian是ueberauth组织开源的一个基于令牌的身份验证库,可用于 Elixir 应用程序。 ueberauth Guardian 2.0.0至2.4.1之前版本存在资源管理错误漏洞,该漏洞源于AtomEncoding编码器未对权限范围进行限制,将攻击者控制的二进制输入直接传递给String.to_atom/1创建原子,导致无限制的原子创建,可能造成拒绝服务。

CVSS 6.9 · Medium EPSS 0.48% · P39

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 2

VendorProduct Version RangeStatus
ueberauth guardian 2.0.0< 2.4.1 affected
b7a6128ca4d0ffb7f7df5219dd982304ff9d6802< 9cd268557846aa4c3ad53566c08f2c190ee5513f affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55733

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation
Source: CVE Program / CVE List V5
Vulnerability Description
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check. The perm_set argument (the application's small, finite set of legitimate permission names) is discarded, so any external string flows straight into atom creation. This encoder is selected with use Guardian.Permissions, encoding: Guardian.Permissions.AtomEncoding and reached through the imported encode/3 entry point. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that funnels attacker-influenced permission scopes (from a request body, a JWT claim, or other external input) into encode/3 therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node with system_limit, taking down every application running on it. The default encoder is Guardian.Permissions.BitwiseEncoding, which is not affected. This issue affects guardian: from 2.0.0 before 2.4.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
ueberauth Guardian 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ueberauth Guardian是ueberauth组织开源的一个基于令牌的身份验证库,可用于 Elixir 应用程序。 ueberauth Guardian 2.0.0至2.4.1之前版本存在资源管理错误漏洞,该漏洞源于AtomEncoding编码器未对权限范围进行限制,将攻击者控制的二进制输入直接传递给String.to_atom/1创建原子,导致无限制的原子创建,可能造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
ueberauth guardian 2.0.0 ~ 2.4.1 cpe:2.3:a:ueberauth:guardian:*:*:*:*:*:*:*:*
ueberauth guardian b7a6128ca4d0ffb7f7df5219dd982304ff9d6802 ~ 9cd268557846aa4c3ad53566c08f2c190ee5513f cpe:2.3:a:ueberauth:guardian:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-55733

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55733

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-55733 (1)

Vendor Advisories for CVE-2026-55733 (3)

Same Patch Batch · ueberauth · 2026-08-01 · 4 CVEs total

CVE-2026-55735 8.2 HIGH Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocatio
CVE-2026-54894 6.9 MEDIUM Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binar
CVE-2026-55734 6.9 MEDIUM guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1

IV. Related Vulnerabilities

V. Comments for CVE-2026-55733

No comments yet


Leave a comment