Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-47079 Round-trip Corruption via Improper Entity Escaping in xml_builder L 2.1 2026-08-21
CVE-2026-48590 Element and Attribute Names Injected Verbatim into XML Output in xml_builder L 2.1 2026-08-21
CVE-2026-47080 CDATA Section Breakout via Unsanitised ]]> in xml_builder L 2.1 2026-08-21
CVE-2026-75484 HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit M 6.9 2026-08-20
CVE-2026-74836 HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit H 8.7 2026-08-20
CVE-2026-53424 Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions C 9.1 2026-08-20
CVE-2026-53425 Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses H 7.6 2026-08-20
CVE-2026-67581 On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay H 8.7 2026-08-19
CVE-2026-73541 Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain H 8.3 2026-08-19
CVE-2026-73136 Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay H 8.2 2026-08-19
CVE-2026-73829 Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race M 6.3 2026-08-19
CVE-2026-43971 Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 M 6.3 2026-08-18
CVE-2026-67579 Filter expression injection via forged keyset pagination cursor in Ash H 7.5 2026-08-12
CVE-2026-64941 Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR L 2.1 2026-08-10
CVE-2026-70395 Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash L 2.1 2026-08-09
CVE-2026-69659 Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset M 5.9 2026-08-09
CVE-2026-67585 Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation H 8.7 2026-08-07
CVE-2026-66838 SQL injection via the :comment option in Postgrex.stream/4 M 5.9 2026-08-07
CVE-2026-68750 Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service H 8.2 2026-08-06
CVE-2026-68749 Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service H 8.2 2026-08-06
CVE-2026-68747 CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input L 2.3 2026-08-06
CVE-2026-66829 html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection L 2.3 2026-08-06
CVE-2026-66370 html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking M 4.8 2026-08-06
CVE-2026-66843 html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding L 2.3 2026-08-06
CVE-2026-66885 Livebook Teams identity callback lacks state binding, allowing login CSRF
ghcr.io / livebook-dev/livebook
M 6.8 2026-08-05
25 per page · 183 CVEs
Page of 8 »