Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
💧 Hex
Not in CISA KEV

CVE-2026-48593 — oban_web

Fix: oban-bg/oban_web@9998b7e

CVE-2026-48593 is a Uncontrolled Resource Consumption vulnerability in oban_web. A fix is available for oban_web — see the affected versions and patch details below.

Unbounded range expansion in cron describe causes memory exhaustion in oban_web

Also known asEEF-CVE-2026-48593GHSA-6xh2-93p9-vqh4
Published
May 26, 2026
Updated
Aug 12, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 26, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-48593.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs38th percentile — riskier than 38% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
💧oban_web

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Hex packages — download data is not available via public APIs for these ecosystems.

Description

Summary

oban_web 2.12.0 introduced a cron expression parser that expands --separated ranges without validating the endpoints. An attacker with access to schedule cron jobs can submit a malicious expression; when any user with dashboard access views the cron job list, Oban.Web.CronExpr.describe/1 is called to render it, triggering allocation of gigabytes of memory and stalling or crashing the BEAM node.

Details

1. Scheduling: The attacker submits a cron job with a malicious expression such as "0 0 1-100000000 * *". No special privilege is required beyond the ability to schedule cron jobs.

2. Parsing: When the cron list is rendered in the dashboard, describe/1 calls parse_range/1 in lib/oban/web/cron_expr.ex, which calls Integer.parse/1 on both endpoints of the range with no bounds check, returning {:range, start_val, end_val} for any integers.

3. Eager expansion: expand_dom_parts/1 and expand_dow_parts/1 materialise the range via Enum.to_list(start_val..end_val). The input above produces ~100 million integers (~2.4 GB). A sibling helper extract_dom_values already validates range bounds, but the expansion helpers do not.

PoC

  1. Schedule a cron job with expression "0 0 1-100000000 * *" (or any expression with an out-of-domain range).
  2. Have any user with Oban.Web dashboard access navigate to the cron job list.
  3. The dashboard calls describe/1 to render the expression, exhausting BEAM memory and crashing the node.

Impact

CVSS 4.0 score 5.9 (Medium). Affects oban_web >= 2.12.0. Requires the ability to schedule a cron job and a dashboard user to view the cron list; no further privileges are needed.

References

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
💧Hexoban_web≥ 2.12.0&&< 2.12.52.12.5mix deps.update oban_web

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for oban_web, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update oban_web to 2.12.5 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-48593 is resolved across your whole dependency graph.

  3. Workarounds

    Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.

Frequently Asked Questions

### Summary `oban_web` 2.12.0 introduced a cron expression parser that expands `-`-separated ranges without validating the endpoints. An attacker with access to schedule cron jobs can submit a malicious expression; when any user with dashboard access views the cron job list, `Oban.Web.CronExpr.describe/1` is called to render it, triggering allocation of gigabytes of memory and stalling or crashing the BEAM node. ### Details **1. Scheduling:** The attacker submits a cron job with a malicious expression such as `"0 0 1-100000000 * *"`. No special privilege is required beyond the ability to sc
O3 Security · Impact-Aware SCA

Is CVE-2026-48593 in your dependencies?

Find it across Hex, including transitive dependencies.

CVE-2026-48593: oban_web | O3 Security