CVE-2026-55733 Details
Description
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check. The perm_set argument (the application's small, finite set of legitimate permission names) is discarded, so any external string flows straight into atom creation. This encoder is selected with use Guardian.Permissions, encoding: Guardian.Permissions.AtomEncoding and reached through the imported encode/3 entry point. String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that funnels attacker-influenced permission scopes (from a request body, a JWT claim, or other external input) into encode/3 therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node with system_limit, taking down every application running on it. The default encoder is Guardian.Permissions.BitwiseEncoding, which is not affected. This issue affects guardian: from 2.0.0 before 2.4.1.
A denial-of-service vulnerability has been identified in Ueberauth Guardian versions 2.0.0 prior to 2.4.1. This issue arises from the 'Guardian.Permissions.AtomEncoding' encoder, which improperly handles permission scopes by passing arbitrary binaries to 'String.to_atom/1' without any allow-list validation. As a result, attacker-controlled input can be used to create an unbounded number of atoms, permanently filling the BEAM atom table and causing the node to crash. This vulnerability affects applications that opt into the 'AtomEncoding' encoder and pass external permission scopes into the 'encode/3' function.
Users can switch the permission encoder to the default 'Guardian.Permissions.BitwiseEncoding' or 'Guardian.Permissions.TextEncoding', both of which do not create atoms. Alternatively, permission values can be validated against the application's allow-list before being passed to the 'encode/3' function.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ueberauth/guardian/security/advisories/GHSA-fjr5-7xrc-hmpj | CISA-ADP | ExploitPatchVendor Advisory |
| https://cna.erlef.org/cves/CVE-2026-55733.html | EEF | Third Party Advisory |
| https://github.com/ueberauth/guardian/commit/9cd268557846aa4c3ad53566c08f2c190ee5513f | EEF | Patch |
| https://github.com/ueberauth/guardian/security/advisories/GHSA-fjr5-7xrc-hmpj | EEF | ExploitPatchVendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-55733 | EEF | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | EEF |
Affected Products
| Product | Versions |
|---|---|
| ueberauth guardian | >= 2.0.0, < 2.4.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2026 | New CVE Received | EEF |