Impact
An attacker that supplies a malicious version string can trigger a denial of service by exploiting the Elixir standard library’s Version module. The parser converts each numeric component—major, minor, patch, and any numeric pre‑release or build identifiers—into integers without imposing a length limit. When a component contains a very long sequence of digits, an uncontrolled arbitrary‑precision conversion (String.to_integer/1) forces the BEAM scheduler to perform a long, non‑yielding Base‑10 to big‑int conversion, consuming CPU and memory. A larger component also raises an uncaught SystemLimitError, crashing the calling process. A roughly one‑megabyte component is enough to exhaust resources, and the vulnerability requires no authentication.
Affected Systems
Elixir releases from 0.9.3 up to, but excluding, 1.20.1 are affected. Any installation of these releases that parses untrusted version strings—such as user‑supplied HTTP parameters, package metadata, or dependency‑manifest fields—faces the risk.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate impact. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote and unauthenticated, as the vulnerable parsing functions are publicly documented entry points and can be invoked by any requester that supplies a malicious version string. Successful exploitation would exhaust CPU and memory resources, potentially halting an application or the BEAM scheduler.
OpenCVE Enrichment