THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-43hj-fxwj-49qw (medium) — membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

[GHSA] GHSA-43hj-fxwj-49qw (medium) — membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

highgithub_advisoriesPublished 2026-08-18

GHSA-43hj-fxwj-49qw Severity: medium CVE: CVE-2026-53423

membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion

### Summary

`membrane_mp4_plugin` interns every 4-byte MP4 box name as a BEAM atom while parsing container headers, with no validation against an allow-list. Any code path that calls `Membrane.MP4.Container.parse/1` (or the bang variant) on attacke

Indicators of compromise

Original source: https://github.com/advisories/GHSA-43hj-fxwj-49qw