THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-54894 — Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom

[NVD] CVE-2026-54894 — Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom

mednvdPublished 2026-08-01

CVE-2026-54894 CVSS: None Published: 2026-08-01T19:16:41.977

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input.

Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atom/1. base_key/1 in lib/guardian/plug/keys.ex converts any

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54894