<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:37:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-375455</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375455</link>
      <description>EUVD-2026-375455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375455</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48597</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint.&lt;/p&gt;
&lt;p&gt;Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list validation. BEAM atoms are never garbage-collected and the atom table is bounded (approximately 1,048,576 entries by default). An attacker who can influence the URL of a Tesla request — either via an application-level URL-forwarding feature (webhook, proxy, importer) or via a Location header returned by a server when Tesla.Middleware.FollowRedirects is in the pipeline — can mint one fresh permanent atom per request by varying the scheme string. After enough requests the atom table fills and the VM crashes, taking down the entire application.&lt;/p&gt;
&lt;p&gt;This issue affects tesla: from 1.3.0 before 1.18.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint.&lt;/p&gt;
&lt;p&gt;Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list validation. BEAM atoms are never garbage-collected and the atom table is bounded (approximately 1,048,576 entries by default). An attacker who can influence the URL of a Tesla request — either via an application-level URL-forwarding feature (webhook, proxy, importer) or via a Location header returned by a server when Tesla.Middleware.FollowRedirects is in the pipeline — can mint one fresh permanent atom per request by varying the scheme string. After enough requests the atom table fills and the VM crashes, taking down the entire application.&lt;/p&gt;
&lt;p&gt;This issue affects tesla: from 1.3.0 before 1.18.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48597</guid>
    </item>
    <item>
      <title>GHSA-h74c-q9j7-mpcm — Tesla vulnerable to atom exhaustion via untrusted URL scheme</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h74c-q9j7-mpcm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: tesla&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In the Mint adapter for the Tesla HTTP client library, `Tesla.Adapter.Mint.open_conn/2` passes the URL scheme of every outgoing request through `String.to_atom/1` with no allow-list validation. Because BEAM atoms are permanent (never garbage-collected) and the atom table is bounded at roughly 1,048,576 entries, an attacker who can vary the URL scheme across requests can mint one fresh atom per request and eventually exhaust the table, crashing the VM.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable call** (`lib/tesla/adapter/mint.ex`, `open_conn/2`): the scheme field parsed from the request URI is passed directly to `String.to_atom/1` before being forwarded to `Mint.HTTP.connect/4`. Even though `Mint` raises for unrecognised schemes, the atom is already interned by that point. The function&amp;#39;s HTTPS-branch guard confirms that no scheme normalisation occurs beforehand.&lt;/p&gt;
&lt;p&gt;The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches `Tesla.get/2` or equivalent. Second, any pipeline that includes `Tesla.Middleware.FollowRedirects`: a server under the attacker&amp;#39;s control can return a `Location` header with a novel scheme, triggering the atom creation on the redirect follow.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Stand up any application that accepts a user-supplied URL and forwards it through `Tesla.Adapter.Mint`.
2. Send requests to the application, each with a distinct, previously unseen URL scheme (e.g. `a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hex: tesla&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;In the Mint adapter for the Tesla HTTP client library, `Tesla.Adapter.Mint.open_conn/2` passes the URL scheme of every outgoing request through `String.to_atom/1` with no allow-list validation. Because BEAM atoms are permanent (never garbage-collected) and the atom table is bounded at roughly 1,048,576 entries, an attacker who can vary the URL scheme across requests can mint one fresh atom per request and eventually exhaust the table, crashing the VM.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable call** (`lib/tesla/adapter/mint.ex`, `open_conn/2`): the scheme field parsed from the request URI is passed directly to `String.to_atom/1` before being forwarded to `Mint.HTTP.connect/4`. Even though `Mint` raises for unrecognised schemes, the atom is already interned by that point. The function&amp;#39;s HTTPS-branch guard confirms that no scheme normalisation occurs beforehand.&lt;/p&gt;
&lt;p&gt;The attack surface has two entry points. First, any application-level URL-forwarding feature (webhook relay, link preview, SSRF-style proxy) where untrusted input reaches `Tesla.get/2` or equivalent. Second, any pipeline that includes `Tesla.Middleware.FollowRedirects`: a server under the attacker&amp;#39;s control can return a `Location` header with a novel scheme, triggering the atom creation on the redirect follow.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Stand up any application that accepts a user-supplied URL and forwards it through `Tesla.Adapter.Mint`.
2. Send requests to the application, each with a distinct, previously unseen URL scheme (e.g. `a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h74c-q9j7-mpcm</guid>
    </item>
  </channel>
</rss>
