WeSearch

Atom Exhaustion Is Not a Footgun. It's One Third of Our CVEs

·2 min read · 0 reactions · 0 comments · 9 views
#security#vulnerability#atom-exhaustion
⚡ TL;DR · AI summary

Atom exhaustion is a significant vulnerability in the BEAM ecosystem, accounting for 35.8% of CVEs published by the Erlang Ecosystem Foundation. This denial-of-service issue arises when atoms are created from user-supplied input, leading to potential crashes of the virtual machine. To mitigate this risk, developers are advised to avoid creating new atoms at runtime and to utilize existing-atom variants or explicit lookup tables instead.

Key facts
Original article
Erlef
Read full at Erlef →
Opening excerpt (first ~120 words) tap to expand

Atom Exhaustion Is Not a Footgun. It's One Third of Our CVEs. May 26, 2026 by Jonatan Männchen Posted in Security Tags security atom-exhaustion vulnerability dos 35.8% of CVEs published by the Erlang Ecosystem Foundation CNA fall into the category of uncontrolled resource consumption. In the BEAM ecosystem, a large share of those are caused by one recurring issue: atom exhaustion. You can find the current distribution on the EEF CNA’s Common Weaknesses page. Atom exhaustion is a denial-of-service vulnerability. Atoms are not garbage collected and are stored in a global atom table, and once it fills up, the VM crashes. Creating atoms from non-finite values, especially user-supplied input, is therefore a latent DoS waiting to happen.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Erlef.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Erlef