Junglewise Threat Intelligence

CVE-2026-53426: leandrocp MDEx atom-table exhaustion in parse_document

CVE-2026-53426 · Severity: info · CVSS 8.2 · Published 2026-06-29

Technologies: Leandrocp Mdex. Vendors: Leandrocp.

Executive brief

A vulnerability in the MDEx Markdown library for Elixir can allow an attacker to crash the entire application server. By providing a specially crafted JSON document, an attacker can exhaust the system's memory for internal identifiers (atoms), which are never cleared. This results in a complete denial-of-service, forcing the entire Erlang virtual machine to shut down and stopping all running processes.

Technical details

The MDEx.parse_document/2 function, when processing a {:json, json} source, utilizes a private function json_to_node/1 that passes attacker-controlled 'node_type' values to Module.concat/1. This internally calls String.to_atom/1, interning a new atom for every unique value provided. Because atoms in the Erlang BEAM VM are not garbage collected, a deeply nested JSON document with unique node types can exhaust the default atom table limit (approximately 1 million). Once this limit is reached, the entire Erlang VM aborts. This is an unauthenticated denial-of-service reachable if the application processes untrusted JSON input via MDEx.

Affected products

  • leandrocp mdex 0.4.3 to 0.13.1

Timeline

  • 2026-06-29: advisory
  • 2026-06-29: disclosed
  • 2026-06-29: patched

References