CVE-2026-49249
Received Received - Intake

Atom Table Exhaustion in Boruta Authorization Server

Vulnerability report for CVE-2026-49249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: GitHub, Inc.

Description

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via String.to_atom/1 before any validation. Because String.to_atom interns atoms permanently in the BEAM atom table (default cap 1,048,576 atoms; ERL_MAX_ATOMS), any authenticated end user can send PUT /users/settings with a user[<fresh-key>]=... body containing fresh keys per request and exhaust the global VM atom table. Once the table is full, the BEAM aborts with no more index entries in atom_tab and the entire OIDC server (auth, admin, gateway apps in the umbrella) crashes. The route is protected only by require_authenticated_user and a per-IP rate limit of 10 requests/second; a logged-in end user can hit it. The keys are atomized unconditionally before the downstream Accounts.update_user/6 call, so even failing updates contribute to exhaustion. This issue has been patched in version 0.10.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
boruta boruta to 0.10.0 (exc)
malach-it boruta_server to 0.10.0 (exc)
malach-it boruta_server 0.10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated denial-of-service vulnerability in Boruta server versions 0.2.0 to 0.9.0. The UserSettingsController.update/2 function converts every key in user-supplied request body into atoms using String.to_atom/1 before validation. Atoms in BEAM VM are permanently stored and never garbage-collected, so an attacker can send crafted PUT requests with many fresh keys to exhaust the global atom table (default limit 1,048,576 atoms), crashing the entire server.

Detection Guidance

Monitor for excessive atom table usage in the BEAM VM by checking the atom count via Erlang shell commands like 'erlang:system_info(atom_count)' or 'erlang:memory(atom_used). If the count approaches the default limit of 1,048,576, investigate PUT requests to /users/settings with unusual key patterns.

Impact Analysis

If exploited, this vulnerability causes a full denial of service across all Boruta server components including OAuth/OIDC endpoints, admin APIs, identity UI, and gateway services. The server crashes when the atom table is exhausted, making the entire authorization server unavailable.

Compliance Impact

This vulnerability causes a denial-of-service condition by crashing the entire OIDC server, which could disrupt authentication and authorization services. For GDPR, this may lead to unauthorized access risks or service unavailability, potentially violating availability requirements under Article 32. For HIPAA, service disruption could impact access to protected health information, affecting integrity and availability requirements.

Mitigation Strategies

Upgrade Boruta server to version 0.10.0 or later, which patches the issue by replacing String.to_atom with String.to_existing_atom or implementing key allowlisting. Temporarily restrict access to the /users/settings endpoint until the upgrade is complete.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49249. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart