Junglewise Threat Intelligence

CVE-2026-55733: ueberauth guardian atom creation DoS in permissions encoding

CVE-2026-55733 · Severity: high · CVSS 7.5 · Published 2026-08-01

Executive brief

Guardian is an authentication library for Elixir applications that handles user permissions and tokens. When configured with the optional AtomEncoding permissions encoder, it converts permission scopes from external sources (API requests, JWT tokens) into Erlang atoms without validation. An attacker can craft many unique permission names to exhaust the fixed atom table, crashing the application and all other services running on the same BEAM virtual machine.

Technical details

The vulnerability exists in Guardian.Permissions.AtomEncoding, which uses String.to_atom/1 to convert permission scope binaries into atoms without allowlist validation. The vulnerable encode_value/3 function discards the perm_set parameter (legitimate permission names) and converts any attacker-supplied string directly to an atom. Since atoms are never garbage collected and the BEAM VM has a fixed atom table (typically ~1M entries), unbounded atom creation from external input exhausts this resource. An unauthenticated attacker can stream varied permission scope values through the encode/3 API to force permanent atom creation, eventually triggering a system_limit crash. This only affects applications explicitly configured with encoding: Guardian.Permissions.AtomEncoding; the default BitwiseEncoding is unaffected. A fix is available in guardian 2.4.1 and later.

Affected products

  • ueberauth guardian 2.0.0 before 2.4.1

Timeline

  • 2026-08-01: disclosed
  • 2026-08-01: patched: Fixed in guardian 2.4.1