CVE-2026-48593 — oban_web
Fix: oban-bg/oban_web@9998b7eCVE-2026-48593 is a Uncontrolled Resource Consumption vulnerability in oban_web. A fix is available for oban_web — see the affected versions and patch details below.
Unbounded range expansion in cron describe causes memory exhaustion in oban_web
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-48593.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
oban_webReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Hex packages — download data is not available via public APIs for these ecosystems.
Description
Summary
oban_web 2.12.0 introduced a cron expression parser that expands --separated ranges without validating the endpoints. An attacker with access to schedule cron jobs can submit a malicious expression; when any user with dashboard access views the cron job list, Oban.Web.CronExpr.describe/1 is called to render it, triggering allocation of gigabytes of memory and stalling or crashing the BEAM node.
Details
1. Scheduling: The attacker submits a cron job with a malicious expression such as "0 0 1-100000000 * *". No special privilege is required beyond the ability to schedule cron jobs.
2. Parsing: When the cron list is rendered in the dashboard, describe/1 calls parse_range/1 in lib/oban/web/cron_expr.ex, which calls Integer.parse/1 on both endpoints of the range with no bounds check, returning {:range, start_val, end_val} for any integers.
3. Eager expansion: expand_dom_parts/1 and expand_dow_parts/1 materialise the range via Enum.to_list(start_val..end_val). The input above produces ~100 million integers (~2.4 GB). A sibling helper extract_dom_values already validates range bounds, but the expansion helpers do not.
PoC
- Schedule a cron job with expression
"0 0 1-100000000 * *"(or any expression with an out-of-domain range). - Have any user with Oban.Web dashboard access navigate to the cron job list.
- The dashboard calls
describe/1to render the expression, exhausting BEAM memory and crashing the node.
Impact
CVSS 4.0 score 5.9 (Medium). Affects oban_web >= 2.12.0. Requires the ability to schedule a cron job and a dashboard user to view the cron list; no further privileges are needed.
References
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 💧Hex | oban_web | ≥ 2.12.0&&< 2.12.5 | 2.12.5mix deps.update oban_web |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for oban_web, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update oban_web to 2.12.5 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-48593 is resolved across your whole dependency graph.
Workarounds
Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.
Frequently Asked Questions
Is CVE-2026-48593 in your dependencies?
Find it across Hex, including transitive dependencies.