← All Advisories

ueberauth Guardian Passes Attacker-Controlled Permission Scope Binaries to String.to_atom Without an Allow-List, Allowing Denial of Service via Atom Table Exhaustion

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-55733

Key Details

CVECVE-2026-55733
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-08-06
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsueberauth guardian
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ueberauthguardian
SubsystemsGeneral OT
SectorsMultiple

What to Know

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input.

Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. When encode/3 in lib/guardian/permissions/atom_encoding.ex is called with a list, each binary entry is handled by the encode_value/3 binary clause, which calls String.to_atom(value) with no allow-list check. The perm_set argument (the application's small, finite set of legitimate permission names) is discarded, so any external string flows straight into atom creation. This encoder is selected with use Guardian.Permissions, encoding: Guardian.Permissions.AtomEncoding and reached through the imported encode/3 entry point.

String.to_atom/1 creates a brand-new atom for every previously unseen binary, atoms are never garbage collected, and the BEAM atom table is fixed at roughly 1,048,576 entries by default. An application that funnels attacker-influenced permission scopes (from a request body, a JWT claim, or other external input) into encode/3 therefore mints one permanent atom per distinct value. A modest stream of varied, unauthenticated input permanently consumes the atom table and crashes the BEAM node with system_limit, taking down every application running on it.

The default encoder is Guardian.Permissions.BitwiseEncoding, which is not affected.

This issue affects guardian: from 2.0.0 before 2.4.1. (NVD)

What to Do

Monitor ueberauth's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-55733
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-55733
Vendor advisoryhttps://github.com/ueberauth/guardian/security/advisories/GHSA-fjr5-7xrc-hmpj