Summary Publication CVE ID Published Date Last Updated
ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
  • pkg:otp/inets
  • pkg:github/erlang/otp
CVE-2026-28808 07 April 2026 07 April 2026
OCSP designated-responder authorization bypass via missing signature verification
  • pkg:otp/public_key
  • pkg:otp/ssl
  • pkg:github/erlang/otp
CVE-2026-32144 07 April 2026 07 April 2026
Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
  • pkg:otp/kernel
  • pkg:github/erlang/otp
CVE-2026-28810 07 April 2026 07 April 2026
Multipart form body parser bypasses body size limits in wisp
  • pkg:hex/wisp
  • pkg:github/gleam-wisp/wisp
CVE-2026-32145 02 April 2026 07 April 2026
XXE in esaml SAML library allows local file read and potential SSRF
  • pkg:hex/esaml
  • pkg:github/arekinath/esaml
  • pkg:github/handnot2/esaml
  • pkg:github/dropbox/esaml
  • pkg:github/Jump-App/esaml
CVE-2026-28809 23 March 2026 07 April 2026
Denial of Service via Oversized Package Upload
  • pkg:github/hexpm/hexpm
  • hexpm / hex.pm
CVE-2026-23940 13 March 2026 06 April 2026
Request smuggling via first-wins Content-Length parsing in inets httpd
  • pkg:otp/inets
  • pkg:github/erlang/otp
CVE-2026-23941 13 March 2026 07 April 2026
Pre-auth SSH DoS via unbounded zlib inflate
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2026-23943 13 March 2026 07 April 2026
SFTP root escape via component-agnostic prefix check in ssh_sftpd
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2026-23942 13 March 2026 07 April 2026
Path Traversal in wisp.serve_static allows arbitrary file read
  • pkg:hex/wisp
  • pkg:github/gleam-wisp/wisp
CVE-2026-28807 10 March 2026 06 April 2026
Improper authorization in device bulk actions and device update API allows cross-organization device control
  • pkg:otp/nerves_hub
  • pkg:oci/nerves-hub
  • pkg:github/nerves-hub/nerves_hub_web
CVE-2026-28806 10 March 2026 06 April 2026
Password Reset Tokens Do Not Expire
  • pkg:github/hexpm/hexpm
  • hexpm / hex.pm
CVE-2026-21622 05 March 2026 06 April 2026
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access
  • pkg:github/hexpm/hexpm
  • hexpm / hex.pm
CVE-2026-21621 05 March 2026 06 April 2026
Unsafe Deserialization of Erlang Terms in hex_core
  • pkg:github/hexpm/hex_core
  • pkg:hex/hex_core
  • pkg:github/hexpm/hex
  • pkg:otp/hex
  • pkg:github/erlang/rebar3
  • pkg:otp/rebar3
CVE-2026-21619 27 February 2026 06 April 2026
Path Traversal in Local File Store Backend
  • pkg:github/hexpm/hexpm
CVE-2026-23939 26 February 2026 07 April 2026
TFTP Path Traversal
  • pkg:github/erlang/otp
  • pkg:otp/inets
  • pkg:otp/tftp
CVE-2026-21620 20 February 2026 07 April 2026
Cross-site scripting (XSS) in OAuth Device Authorization screen
  • pkg:github/hexpm/hexpm
  • hexpm / hex.pm
CVE-2026-21618 19 January 2026 06 April 2026
Authorization bypass when bypass policy condition evaluates to true
  • pkg:hex/ash
  • pkg:github/ash-project/ash
CVE-2025-48044 17 October 2025 06 April 2026
Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization
  • pkg:hex/ash
  • pkg:github/ash-project/ash
CVE-2025-48043 10 October 2025 06 April 2026
SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2025-48041 11 September 2025 07 April 2026
Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2025-48040 11 September 2025 06 April 2026
Unverified Paths can Cause Excessive Use of System Resources
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2025-48039 11 September 2025 07 April 2026
Unverified File Handles can Cause Excessive Use of System Resources
  • pkg:otp/ssh
  • pkg:github/erlang/otp
CVE-2025-48038 11 September 2025 07 April 2026
Before action hooks may execute in certain scenarios despite a request being forbidden
  • pkg:hex/ash
  • pkg:github/ash-project/ash
CVE-2025-48042 07 September 2025 06 April 2026
Missing Session Revocation on Logout in ash_authentication_phoenix
  • pkg:hex/ash_authentication_phoenix
  • pkg:github/team-alembic/ash_authentication_phoenix
CVE-2025-4754 17 June 2025 06 April 2026
Absolute path traversal in zip:unzip/1,2
  • pkg:otp/stdlib
  • pkg:github/erlang/otp
CVE-2025-4748 16 June 2025 06 April 2026

CVE’s can also be requested as a JSON: GET /cves/index.json

OSV records can also be requested as a JSON: GET /osv/all.json