CVE-2026-54894 | Ueberauth Guardian up to 2.4.0 Plug Keys keys.ex String.to_atom key allocation of resources

SecurityVulns

A vulnerability classified as problematic has been found in Ueberauth Guardian up to 2.4.0. Affected is the function String.to_atom of the file lib/guardian/plug/keys.ex of the component Plug Keys. The manipulation of the argument key leads to allocation of resources.

This vulnerability is uniquely identified as CVE-2026-54894. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More