What is CVE-2026-54894?
CVE-2026-54894 is a vulnerability in the ueberauth guardian library involving resource allocation without limits or throttling. It allows denial of service through unbounded atom creation from attacker-influenced binary input, specifically via the String.to_atom/1 function in key derivation. Affected systems should implement proper input validation to prevent exploitation.
Azərbaycanca: CVE-2026-54894, ueberauth guardian kitabxanasında resursların limitsiz idarə edilməsi zəifliyidir. Bu, təcavüzkarın təsir etdiyi binary giriş vasitəsilə limitsiz atom yaradılmasına yol açaraq denial of service hücumlarına səbəb ola bilər. Təsirlənmiş sistemlərdə String.to_atom/1 funksiyasının təhlükəsiz istifadəsi təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: ueberauth
FAQ2
Which library is affected by CVE-2026-54894?
CVE-2026-54894 was discovered in the ueberauth guardian library.
What is the potential impact of exploiting CVE-2026-54894?
This vulnerability can lead to denial of service (DoS) attacks through unbounded atom creation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.