THREAT OPS › Threat News › [GHSA] GHSA-43hj-fxwj-49qw (medium) — membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
[GHSA] GHSA-43hj-fxwj-49qw (medium) — membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
GHSA-43hj-fxwj-49qw Severity: medium CVE: CVE-2026-53423
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
### Summary
`membrane_mp4_plugin` interns every 4-byte MP4 box name as a BEAM atom while parsing container headers, with no validation against an allow-list. Any code path that calls `Membrane.MP4.Container.parse/1` (or the bang variant) on attacke
Indicators of compromise
- ae4bf04c393aa1562f3df3d33e20bc5cb8130de2sha1
- 56373d1ddc86968e55fbde795c14eeba24357b57sha1
- CVE-2026-53423cve
Original source: https://github.com/advisories/GHSA-43hj-fxwj-49qw