guardian
Hex4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting guardianpage 1 of 1
- CVE-2026-54894HIGHCVSS 7.5EG 7.5✓ Fixed in 2.4.12026-08-01
vulnerable: 0.1.0 ... 2.4.0 (53 versions)
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by pas…
- CVE-2026-55733HIGHCVSS 7.5EG 7.5✓ Fixed in 2.4.12026-08-01
vulnerable: 2.0.0 ... 2.4.0 (12 versions)
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing …
- CVE-2026-55734HIGHCVSS 7.5EG 7.5✓ Fixed in 2.4.12026-08-01
vulnerable: 2.0.0 ... 2.4.0 (12 versions)
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guard…
- CVE-2026-55735HIGHCVSS 7.5EG 7.5✓ Fixed in 2.4.12026-08-01
vulnerable: 1.0.0 ... 2.4.0 (18 versions)
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which…
Check whether guardian is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for guardian CVEs against the assets you own.
Start Free Scan →