Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-94206 Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds M 6.3 2026-10-06
CVE-2026-95105 Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping H 8.2 2026-10-06
CVE-2026-94201 Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash H 8.2 2026-10-05
CVE-2026-94194 Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries M 6.3 2026-09-28
CVE-2026-92103 Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size M 6.3 2026-09-28
CVE-2026-91043 HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory H 8.2 2026-09-28
CVE-2026-92106 lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS L 2.3 2026-09-25
CVE-2026-93477 Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash M 5.9 2026-09-25
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy C 9.3 2026-09-24
CVE-2026-86698 Refresh tokens accepted as private repository credentials at the CDN L 2.3 2026-09-22
CVE-2026-87119 mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed H 8.2 2026-09-22
CVE-2026-89420 Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free H 7.1 2026-09-22
CVE-2026-65634 Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder
Erlang
pkg:otp/asn1
H 8.2 2026-09-22
CVE-2026-68956 SSH daemon allocates unbounded idle session channels, bypassing max_channels
Erlang
pkg:otp/ssh
H 7.1 2026-09-22
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
Erlang
Erlang / ssl
C 9.3 2026-09-22
CVE-2026-82672 Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections M 6.3 2026-09-19
CVE-2026-86688 Session id is not renewed on authentication in ash_authentication, allowing session fixation H 7.4 2026-09-17
CVE-2026-76949 Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement C 9.1 2026-09-17
CVE-2026-91039 dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover C 9.1 2026-09-17
CVE-2026-88952 OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication C 9.1 2026-09-17
CVE-2026-85500 `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication C 9.1 2026-09-17
CVE-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix C 9.1 2026-09-17
CVE-2026-81632 Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix H 7.2 2026-09-17
CVE-2026-80218 Sign-in token minted for one resource accepted by another in AshAuthentication H 7.6 2026-09-17
CVE-2026-78223 Token revocation record built from unverified JWT claims in AshAuthentication M 6.9 2026-09-17
25 per page · 320 CVEs
Page of 13 »