SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-54894

HIGH · CVSS 7.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to exploit the ueberauth guardian by sending unbounded binary input, leading to the creation of an excessive number of atoms in the BEAM atom table, which can result in a denial of service (DoS) by exhausting available atom slots. This affects versions of the guardian library from 0.1.0 to before 2.4.1, making it critical for applications utilizing this library to prioritize patching or upgrading to mitigate potential service disruptions. Organizations relying on the guardian library for authentication should assess their exposure and implement necessary safeguards immediately.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54894
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. base_key/1 in lib/guardian/plug/keys.ex converts any binary into the atom :"guardian_<input>", and the derived helpers claims_key/1, resource_key/1, and token_key/1 create a second atom on top of that. key_from_other/1 likewise converts a regex-captured binary through String.to_atom/1. The public specs advertise String.t() as a valid argument, so passing a string is documented usage, and higher-level entry points such as Guardian.Plug.current_token(conn, key: key) thread the caller-supplied key straight into these functions. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that routes attacker-influenced data (a tenant identifier, header, or other request input) into a Guardian key therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node, taking down every application running on it. This issue affects guardian: from 0.1.0 before 2.4.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)