Executive brief
A vulnerability in the MDEx Markdown library for Elixir can allow an attacker to crash the entire application server. By providing a specially crafted JSON document, an attacker can exhaust the system's memory for internal identifiers (atoms), which are never cleared. This results in a complete denial-of-service, forcing the entire Erlang virtual machine to shut down and stopping all running processes.
Technical details
The MDEx.parse_document/2 function, when processing a {:json, json} source, utilizes a private function json_to_node/1 that passes attacker-controlled 'node_type' values to Module.concat/1. This internally calls String.to_atom/1, interning a new atom for every unique value provided. Because atoms in the Erlang BEAM VM are not garbage collected, a deeply nested JSON document with unique node types can exhaust the default atom table limit (approximately 1 million). Once this limit is reached, the entire Erlang VM aborts. This is an unauthenticated denial-of-service reachable if the application processes untrusted JSON input via MDEx.
Affected products
- leandrocp mdex 0.4.3 to 0.13.1
Timeline
- 2026-06-29: advisory
- 2026-06-29: disclosed
- 2026-06-29: patched