{"id":"GHSA-43hj-fxwj-49qw","summary":"membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion","details":"### Summary\n\n`membrane_mp4_plugin` interns every 4-byte MP4 box name as a BEAM atom while parsing container headers, with no validation against an allow-list. Any code path that calls `Membrane.MP4.Container.parse/1` (or the bang variant) on attacker-controlled MP4 bytes can be made to exhaust the BEAM atom table, which is uncapped at the source but bounded by the runtime ceiling (around 1,048,576 atoms) and never garbage-collected. Once the ceiling is hit, the entire BEAM node aborts.\n\n### Details\n\nThe MP4 container parser walks the input stream box-by-box. For each box, `Membrane.MP4.Container.Header.parse/1` in `lib/membrane_mp4/container/header.ex` extracts the 4-byte name field and delegates to the private helper `parse_box_name/1`, which trims trailing spaces and passes the bytes through `String.to_atom/1`. Because `String.to_atom/1` creates a new atom unconditionally, every distinct attacker-chosen 4-byte sequence becomes a permanent allocation in the global atom table. Atoms are not subject to garbage collection, so unique names accumulate for the lifetime of the node.\n\nThe fix replaces the unsafe interning with `String.to_existing_atom/1` and treats unknown names as the `:unknown` atom downstream (with related plumbing in `parse_helper.ex`, `serialize_helper.ex`, and the ISOM/CMAF demuxer engines so the new error variant flows through cleanly).\n\n### PoC\n\n1. Generate an MP4-shaped payload of roughly 1.1 million minimal box headers, each 8 bytes long (4-byte size of 8, followed by a unique 4-byte ASCII name produced by enumerating combinations in the printable range).\n2. Concatenate them into a single binary (~8 MB total).\n3. Call `Membrane.MP4.Container.parse!/1` on the binary inside any process running under the target BEAM node.\n4. The node aborts once the atom table ceiling is reached.\n\n### Impact\n\nAn attacker who can get a single crafted MP4 file in front of any system that demuxes user-supplied media with `membrane_mp4_plugin` can crash the entire BEAM node hosting that pipeline, taking down every Erlang/Elixir application sharing the runtime. No authentication, network position, or user interaction is required beyond delivering the file to whatever processing path eventually calls the parser.\n\n### References\n\n* Introduction commit: https://github.com/membraneframework/membrane_mp4_plugin/commit/ae4bf04c393aa1562f3df3d33e20bc5cb8130de2\n* Patch commit: https://github.com/membraneframework/membrane_mp4_plugin/commit/56373d1ddc86968e55fbde795c14eeba24357b57","aliases":["CVE-2026-53423","EEF-CVE-2026-53423"],"modified":"2026-08-18T20:30:07.373842846Z","published":"2026-08-18T20:16:29Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-18T20:16:29Z","nvd_published_at":"2026-06-11T12:16:31Z","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/membraneframework/membrane_mp4_plugin/security/advisories/GHSA-43hj-fxwj-49qw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53423"},{"type":"WEB","url":"https://github.com/membraneframework/membrane_mp4_plugin/commit/56373d1ddc86968e55fbde795c14eeba24357b57"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-53423.html"},{"type":"PACKAGE","url":"https://github.com/membraneframework/membrane_mp4_plugin"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-53423"}],"affected":[{"package":{"name":"membrane_mp4_plugin","ecosystem":"Hex","purl":"pkg:hex/membrane_mp4_plugin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.36.7"}]}],"versions":["0.10.0","0.11.0","0.12.0","0.12.1","0.13.0","0.14.0","0.15.0","0.16.0","0.16.1","0.16.2","0.17.0","0.18.0","0.18.1","0.19.0","0.20.0","0.21.0","0.22.0","0.22.1","0.22.2","0.22.3","0.23.0","0.24.0","0.24.1","0.25.0","0.26.0","0.26.1","0.27.0","0.28.0","0.28.1","0.29.0","0.29.1","0.3.0","0.30.0","0.30.1","0.30.2","0.31.0","0.32.0","0.33.0","0.33.1","0.34.0","0.34.1","0.34.2","0.35.0","0.35.1","0.35.2","0.35.3","0.36.0","0.36.1","0.36.2","0.36.3","0.36.4","0.36.5","0.36.6","0.4.0","0.5.0","0.6.0","0.7.0","0.8.0","0.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-43hj-fxwj-49qw/GHSA-43hj-fxwj-49qw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}