[{"id":"CVE-2026-82750","title":"Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation","details":"/cves/CVE-2026-82750.json","datePublished":"2026-09-06T16:08:41Z","dateUpdated":"2026-09-06T16:08:41Z"},{"id":"CVE-2026-82751","title":"Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning","details":"/cves/CVE-2026-82751.json","datePublished":"2026-09-06T16:07:26Z","dateUpdated":"2026-09-06T16:07:26Z"},{"id":"CVE-2026-82752","title":"Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length","details":"/cves/CVE-2026-82752.json","datePublished":"2026-09-05T17:16:16Z","dateUpdated":"2026-09-05T17:16:16Z"},{"id":"CVE-2026-82728","title":"Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS","details":"/cves/CVE-2026-82728.json","datePublished":"2026-09-04T14:31:30Z","dateUpdated":"2026-09-04T19:32:44Z"},{"id":"CVE-2026-82729","title":"Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS","details":"/cves/CVE-2026-82729.json","datePublished":"2026-09-04T14:31:20Z","dateUpdated":"2026-09-04T19:33:32Z"},{"id":"CVE-2026-69664","title":"httpd parks a request worker indefinitely on a malformed chunk size sent after the headers","details":"/cves/CVE-2026-69664.json","datePublished":"2026-09-01T14:59:03Z","dateUpdated":"2026-09-01T17:45:20Z"},{"id":"CVE-2026-70409","title":"eldap does not bound the port component of a referral URL before integer conversion","details":"/cves/CVE-2026-70409.json","datePublished":"2026-09-01T14:51:00Z","dateUpdated":"2026-09-01T17:54:18Z"},{"id":"CVE-2026-70405","title":"snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields","details":"/cves/CVE-2026-70405.json","datePublished":"2026-09-01T14:50:34Z","dateUpdated":"2026-09-01T18:10:13Z"},{"id":"CVE-2026-66835","title":"httpd mod_auth directory protection bypassed by a doubled slash in the request path","details":"/cves/CVE-2026-66835.json","datePublished":"2026-09-01T14:49:47Z","dateUpdated":"2026-09-01T17:58:31Z"},{"id":"CVE-2026-73270","title":"httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems","details":"/cves/CVE-2026-73270.json","datePublished":"2026-09-01T14:48:53Z","dateUpdated":"2026-09-01T15:58:41Z"},{"id":"CVE-2026-75538","title":"A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer","details":"/cves/CVE-2026-75538.json","datePublished":"2026-09-01T14:48:26Z","dateUpdated":"2026-09-01T15:58:16Z"},{"id":"CVE-2026-74994","title":"inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth","details":"/cves/CVE-2026-74994.json","datePublished":"2026-09-01T14:45:57Z","dateUpdated":"2026-09-01T15:57:51Z"},{"id":"CVE-2026-74835","title":"inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception","details":"/cves/CVE-2026-74835.json","datePublished":"2026-09-01T14:45:16Z","dateUpdated":"2026-09-01T15:57:22Z"},{"id":"CVE-2026-73812","title":"inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length","details":"/cves/CVE-2026-73812.json","datePublished":"2026-09-01T14:42:42Z","dateUpdated":"2026-09-01T15:56:45Z"},{"id":"CVE-2026-73276","title":"inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i","details":"/cves/CVE-2026-73276.json","datePublished":"2026-09-01T14:41:24Z","dateUpdated":"2026-09-01T15:55:30Z"},{"id":"CVE-2026-66357","title":"inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation","details":"/cves/CVE-2026-66357.json","datePublished":"2026-09-01T14:40:50Z","dateUpdated":"2026-09-01T15:56:07Z"},{"id":"CVE-2026-59696","title":"uri_string does not bound the port component of a URI before integer conversion","details":"/cves/CVE-2026-59696.json","datePublished":"2026-09-01T14:37:33Z","dateUpdated":"2026-09-01T15:54:49Z"},{"id":"CVE-2026-55951","title":"httpc memory exhaustion via unbounded response header accumulation","details":"/cves/CVE-2026-55951.json","datePublished":"2026-09-01T14:37:02Z","dateUpdated":"2026-09-01T15:54:18Z"},{"id":"CVE-2026-71380","title":"httpd applies no timeout while receiving a request body, parking a worker on a stalled client","details":"/cves/CVE-2026-71380.json","datePublished":"2026-09-01T14:35:31Z","dateUpdated":"2026-09-01T15:52:08Z"},{"id":"CVE-2026-71562","title":"httpc does not bound server-supplied numeric header values before integer conversion","details":"/cves/CVE-2026-71562.json","datePublished":"2026-09-01T14:33:41Z","dateUpdated":"2026-09-01T15:53:23Z"},{"id":"CVE-2026-70399","title":"httpd does not enforce the documented default max_clients connection limit","details":"/cves/CVE-2026-70399.json","datePublished":"2026-09-01T14:33:05Z","dateUpdated":"2026-09-01T15:52:53Z"},{"id":"CVE-2026-82747","title":"Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor","details":"/cves/CVE-2026-82747.json","datePublished":"2026-09-01T04:14:57Z","dateUpdated":"2026-09-01T12:36:50Z"},{"id":"CVE-2026-82749","title":"Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records","details":"/cves/CVE-2026-82749.json","datePublished":"2026-09-01T03:54:12Z","dateUpdated":"2026-09-01T12:38:27Z"},{"id":"CVE-2026-82748","title":"Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another","details":"/cves/CVE-2026-82748.json","datePublished":"2026-09-01T03:52:01Z","dateUpdated":"2026-09-01T15:17:47Z"},{"id":"CVE-2026-82746","title":"Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records","details":"/cves/CVE-2026-82746.json","datePublished":"2026-09-01T03:47:14Z","dateUpdated":"2026-09-01T15:17:12Z"},{"id":"CVE-2026-82745","title":"ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness","details":"/cves/CVE-2026-82745.json","datePublished":"2026-09-01T03:42:28Z","dateUpdated":"2026-09-01T15:16:38Z"},{"id":"CVE-2026-82744","title":"Ash.Reactor change step fails open, skipping a change when its where guard raises","details":"/cves/CVE-2026-82744.json","datePublished":"2026-09-01T03:39:42Z","dateUpdated":"2026-09-01T15:15:56Z"},{"id":"CVE-2026-82743","title":"Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads","details":"/cves/CVE-2026-82743.json","datePublished":"2026-09-01T03:37:24Z","dateUpdated":"2026-09-01T12:40:17Z"},{"id":"CVE-2026-82742","title":"Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory","details":"/cves/CVE-2026-82742.json","datePublished":"2026-09-01T03:35:18Z","dateUpdated":"2026-09-01T12:41:53Z"},{"id":"CVE-2026-82741","title":"Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion","details":"/cves/CVE-2026-82741.json","datePublished":"2026-09-01T03:33:03Z","dateUpdated":"2026-09-01T15:13:10Z"},{"id":"CVE-2026-82740","title":"Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs","details":"/cves/CVE-2026-82740.json","datePublished":"2026-09-01T03:29:11Z","dateUpdated":"2026-09-01T12:42:58Z"},{"id":"CVE-2026-82739","title":"Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error","details":"/cves/CVE-2026-82739.json","datePublished":"2026-09-01T03:27:58Z","dateUpdated":"2026-09-01T12:44:21Z"},{"id":"CVE-2026-82738","title":"Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service","details":"/cves/CVE-2026-82738.json","datePublished":"2026-09-01T03:26:23Z","dateUpdated":"2026-09-01T12:47:34Z"},{"id":"CVE-2026-82737","title":"Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads","details":"/cves/CVE-2026-82737.json","datePublished":"2026-09-01T03:24:14Z","dateUpdated":"2026-09-01T12:56:53Z"},{"id":"CVE-2026-82736","title":"Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass","details":"/cves/CVE-2026-82736.json","datePublished":"2026-09-01T03:21:47Z","dateUpdated":"2026-09-01T13:06:35Z"},{"id":"CVE-2026-82735","title":"Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service","details":"/cves/CVE-2026-82735.json","datePublished":"2026-09-01T03:19:36Z","dateUpdated":"2026-09-01T13:11:14Z"},{"id":"CVE-2026-82734","title":"Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal","details":"/cves/CVE-2026-82734.json","datePublished":"2026-09-01T03:17:15Z","dateUpdated":"2026-09-01T15:15:19Z"},{"id":"CVE-2026-82731","title":"Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection","details":"/cves/CVE-2026-82731.json","datePublished":"2026-09-01T02:09:38Z","dateUpdated":"2026-09-01T15:13:54Z"},{"id":"CVE-2026-74837","title":"Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter","details":"/cves/CVE-2026-74837.json","datePublished":"2026-09-01T02:09:30Z","dateUpdated":"2026-09-01T15:13:07Z"},{"id":"CVE-2026-82733","title":"Route handler return value echoed into AshTypescript error response","details":"/cves/CVE-2026-82733.json","datePublished":"2026-09-01T02:09:22Z","dateUpdated":"2026-09-01T15:12:07Z"},{"id":"CVE-2026-82732","title":"Declared argument constraints not enforced on AshTypescript typed controller routes","details":"/cves/CVE-2026-82732.json","datePublished":"2026-09-01T02:09:15Z","dateUpdated":"2026-09-01T14:55:02Z"},{"id":"CVE-2026-82730","title":"Authorization-redacted field values disclosed through AshTypescript result normalization","details":"/cves/CVE-2026-82730.json","datePublished":"2026-09-01T02:09:01Z","dateUpdated":"2026-09-01T14:54:16Z"},{"id":"CVE-2026-77950","title":"RPC error handler fails open in AshTypescript, disclosing unredacted errors","details":"/cves/CVE-2026-77950.json","datePublished":"2026-09-01T02:08:54Z","dateUpdated":"2026-09-01T14:53:26Z"},{"id":"CVE-2026-77856","title":"Unbounded atom creation from typed struct field names in AshTypescript field selector","details":"/cves/CVE-2026-77856.json","datePublished":"2026-09-01T02:08:46Z","dateUpdated":"2026-09-01T14:49:22Z"},{"id":"CVE-2026-82725","title":"AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data","details":"/cves/CVE-2026-82725.json","datePublished":"2026-08-31T03:09:25Z","dateUpdated":"2026-08-31T15:49:46Z"},{"id":"CVE-2026-82724","title":"Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain","details":"/cves/CVE-2026-82724.json","datePublished":"2026-08-31T03:07:57Z","dateUpdated":"2026-08-31T15:54:49Z"},{"id":"CVE-2026-82726","title":"AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant","details":"/cves/CVE-2026-82726.json","datePublished":"2026-08-31T03:05:38Z","dateUpdated":"2026-08-31T14:47:35Z"},{"id":"CVE-2026-82727","title":"AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message","details":"/cves/CVE-2026-82727.json","datePublished":"2026-08-31T03:03:58Z","dateUpdated":"2026-08-31T14:49:25Z"},{"id":"CVE-2026-82673","title":"Path traversal in AshAdmin file uploads via unsanitized client filename","details":"/cves/CVE-2026-82673.json","datePublished":"2026-08-31T02:33:10Z","dateUpdated":"2026-08-31T14:50:14Z"},{"id":"CVE-2026-81853","title":"AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle","details":"/cves/CVE-2026-81853.json","datePublished":"2026-08-31T02:31:29Z","dateUpdated":"2026-08-31T15:58:40Z"},{"id":"CVE-2026-81852","title":"AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass","details":"/cves/CVE-2026-81852.json","datePublished":"2026-08-31T02:29:14Z","dateUpdated":"2026-08-31T15:59:44Z"},{"id":"CVE-2026-82681","title":"Query-parameter injection in AshAdmin row-action links via unencoded string primary keys","details":"/cves/CVE-2026-82681.json","datePublished":"2026-08-31T02:26:05Z","dateUpdated":"2026-08-31T16:01:32Z"},{"id":"CVE-2026-77850","title":"Stored XSS in AshAdmin relationship typeahead via unescaped label_field content","details":"/cves/CVE-2026-77850.json","datePublished":"2026-08-31T02:23:54Z","dateUpdated":"2026-08-31T16:05:15Z"},{"id":"CVE-2026-82722","title":"AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)","details":"/cves/CVE-2026-82722.json","datePublished":"2026-08-31T02:22:15Z","dateUpdated":"2026-08-31T16:07:01Z"},{"id":"CVE-2026-75757","title":"AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain","details":"/cves/CVE-2026-75757.json","datePublished":"2026-08-31T02:20:17Z","dateUpdated":"2026-08-31T14:50:59Z"},{"id":"CVE-2026-75760","title":"AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error","details":"/cves/CVE-2026-75760.json","datePublished":"2026-08-31T01:09:59Z","dateUpdated":"2026-08-31T16:07:25Z"},{"id":"CVE-2026-82580","title":"AshAi echoes raw tool exception messages into the conversation, disclosing internal details","details":"/cves/CVE-2026-82580.json","datePublished":"2026-08-31T01:09:00Z","dateUpdated":"2026-08-31T16:06:44Z"},{"id":"CVE-2026-82579","title":"AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service","details":"/cves/CVE-2026-82579.json","datePublished":"2026-08-31T01:07:49Z","dateUpdated":"2026-08-31T16:05:58Z"},{"id":"CVE-2026-82564","title":"Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records","details":"/cves/CVE-2026-82564.json","datePublished":"2026-08-31T01:06:00Z","dateUpdated":"2026-09-01T17:18:18Z"},{"id":"CVE-2026-81315","title":"MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header","details":"/cves/CVE-2026-81315.json","datePublished":"2026-08-31T00:57:55Z","dateUpdated":"2026-08-31T16:02:38Z"},{"id":"CVE-2026-77956","title":"EEx template evaluation of prompt content in AshAi enables remote code execution","details":"/cves/CVE-2026-77956.json","datePublished":"2026-08-31T00:56:26Z","dateUpdated":"2026-08-31T16:01:41Z"},{"id":"CVE-2026-78693","title":"Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names","details":"/cves/CVE-2026-78693.json","datePublished":"2026-08-30T18:28:35Z","dateUpdated":"2026-08-31T15:58:48Z"},{"id":"CVE-2026-80223","title":"Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read","details":"/cves/CVE-2026-80223.json","datePublished":"2026-08-30T18:27:09Z","dateUpdated":"2026-08-31T15:58:00Z"},{"id":"CVE-2026-81636","title":"Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service","details":"/cves/CVE-2026-81636.json","datePublished":"2026-08-30T18:25:29Z","dateUpdated":"2026-08-31T15:57:06Z"},{"id":"CVE-2026-81633","title":"Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment","details":"/cves/CVE-2026-81633.json","datePublished":"2026-08-30T18:22:07Z","dateUpdated":"2026-08-31T15:56:01Z"},{"id":"CVE-2026-81643","title":"Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification","details":"/cves/CVE-2026-81643.json","datePublished":"2026-08-30T18:20:35Z","dateUpdated":"2026-08-31T15:01:05Z"},{"id":"CVE-2026-82367","title":"Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic","details":"/cves/CVE-2026-82367.json","datePublished":"2026-08-30T18:17:13Z","dateUpdated":"2026-09-01T15:37:34Z"},{"id":"CVE-2026-81322","title":"Cloaked plaintext leaks through a non-sensitive action argument in AshCloak","details":"/cves/CVE-2026-81322.json","datePublished":"2026-08-30T18:06:33Z","dateUpdated":"2026-09-01T12:34:57Z"},{"id":"CVE-2026-81319","title":"Unsafe deserialization of decrypted terms enables node DoS in AshCloak","details":"/cves/CVE-2026-81319.json","datePublished":"2026-08-30T18:05:13Z","dateUpdated":"2026-09-01T12:32:46Z"},{"id":"CVE-2026-78699","title":"rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres","details":"/cves/CVE-2026-78699.json","datePublished":"2026-08-30T15:13:23Z","dateUpdated":"2026-09-01T12:30:30Z"},{"id":"CVE-2026-77454","title":"exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql","details":"/cves/CVE-2026-77454.json","datePublished":"2026-08-30T12:01:23Z","dateUpdated":"2026-08-31T15:00:02Z"},{"id":"CVE-2026-81316","title":"Same-named aggregates with differing filters are conflated in AshSql","details":"/cves/CVE-2026-81316.json","datePublished":"2026-08-30T11:59:41Z","dateUpdated":"2026-08-31T14:59:22Z"},{"id":"CVE-2026-81318","title":"Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql","details":"/cves/CVE-2026-81318.json","datePublished":"2026-08-30T11:56:52Z","dateUpdated":"2026-08-31T16:59:41Z"},{"id":"CVE-2026-78691","title":"Unescaped backslash allows LIKE wildcard injection in AshSql string search","details":"/cves/CVE-2026-78691.json","datePublished":"2026-08-30T11:55:20Z","dateUpdated":"2026-08-31T14:57:41Z"},{"id":"CVE-2026-80227","title":"SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql","details":"/cves/CVE-2026-80227.json","datePublished":"2026-08-30T11:53:35Z","dateUpdated":"2026-08-31T14:56:51Z"},{"id":"CVE-2026-78228","title":"Unbounded handle_error recursion enables denial of service in AshOban triggers","details":"/cves/CVE-2026-78228.json","datePublished":"2026-08-30T11:51:49Z","dateUpdated":"2026-08-31T14:56:07Z"},{"id":"CVE-2026-78038","title":"Job argument injection via :args overrides primary_key and tenant in AshOban","details":"/cves/CVE-2026-78038.json","datePublished":"2026-08-30T11:50:21Z","dateUpdated":"2026-08-31T14:55:17Z"},{"id":"CVE-2026-77846","title":"JSON path injection via unescaped get_path segments in AshSqlite","details":"/cves/CVE-2026-77846.json","datePublished":"2026-08-30T02:52:12Z","dateUpdated":"2026-08-31T14:54:22Z"},{"id":"CVE-2026-75759","title":"Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc","details":"/cves/CVE-2026-75759.json","datePublished":"2026-08-30T01:12:43Z","dateUpdated":"2026-08-31T14:53:35Z"},{"id":"CVE-2026-77831","title":"Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking","details":"/cves/CVE-2026-77831.json","datePublished":"2026-08-30T00:18:38Z","dateUpdated":"2026-08-31T14:52:45Z"},{"id":"CVE-2026-77970","title":"Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions","details":"/cves/CVE-2026-77970.json","datePublished":"2026-08-30T00:18:22Z","dateUpdated":"2026-08-31T14:51:59Z"},{"id":"CVE-2026-75847","title":"Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail","details":"/cves/CVE-2026-75847.json","datePublished":"2026-08-30T00:18:05Z","dateUpdated":"2026-08-31T17:03:22Z"},{"id":"CVE-2026-75758","title":"Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir","details":"/cves/CVE-2026-75758.json","datePublished":"2026-08-28T11:28:53Z","dateUpdated":"2026-08-28T18:29:23Z"},{"id":"CVE-2026-66353","title":"Doggo vulnerable to cross-site scripting via unescaped date field values","details":"/cves/CVE-2026-66353.json","datePublished":"2026-08-27T16:44:59Z","dateUpdated":"2026-08-28T14:13:54Z"},{"id":"CVE-2026-65633","title":"Purpose-limited JWT accepted as full bearer authentication in AshAuthentication","details":"/cves/CVE-2026-65633.json","datePublished":"2026-08-25T08:03:51Z","dateUpdated":"2026-08-25T19:49:22Z"},{"id":"CVE-2026-66882","title":"Reflected XSS in AshAuthentication confirmation and magic link interaction forms","details":"/cves/CVE-2026-66882.json","datePublished":"2026-08-25T08:03:47Z","dateUpdated":"2026-08-25T19:51:21Z"},{"id":"CVE-2026-75554","title":"Explicit organization scopes survive token refresh after membership ends","details":"/cves/CVE-2026-75554.json","datePublished":"2026-08-24T20:15:05Z","dateUpdated":"2026-08-25T19:53:55Z"},{"id":"CVE-2026-75542","title":"OAuth token exchange grants repository scopes for organizations the principal cannot access","details":"/cves/CVE-2026-75542.json","datePublished":"2026-08-24T20:14:30Z","dateUpdated":"2026-08-25T19:53:26Z"},{"id":"CVE-2026-47079","title":"Round-trip Corruption via Improper Entity Escaping in xml_builder","details":"/cves/CVE-2026-47079.json","datePublished":"2026-08-21T09:52:44Z","dateUpdated":"2026-08-21T12:19:47Z"},{"id":"CVE-2026-48590","title":"Element and Attribute Names Injected Verbatim into XML Output in xml_builder","details":"/cves/CVE-2026-48590.json","datePublished":"2026-08-21T09:51:25Z","dateUpdated":"2026-08-21T12:25:33Z"},{"id":"CVE-2026-47080","title":"CDATA Section Breakout via Unsanitised ]]> in xml_builder","details":"/cves/CVE-2026-47080.json","datePublished":"2026-08-21T09:49:34Z","dateUpdated":"2026-08-21T12:32:15Z"},{"id":"CVE-2026-75484","title":"HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit","details":"/cves/CVE-2026-75484.json","datePublished":"2026-08-20T21:11:27Z","dateUpdated":"2026-08-21T19:52:42Z"},{"id":"CVE-2026-74836","title":"HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit","details":"/cves/CVE-2026-74836.json","datePublished":"2026-08-20T21:11:18Z","dateUpdated":"2026-08-21T19:55:01Z"},{"id":"CVE-2026-53424","title":"Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions","details":"/cves/CVE-2026-53424.json","datePublished":"2026-08-20T17:27:11Z","dateUpdated":"2026-08-21T19:42:21Z"},{"id":"CVE-2026-53425","title":"Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses","details":"/cves/CVE-2026-53425.json","datePublished":"2026-08-20T17:26:35Z","dateUpdated":"2026-08-21T19:50:34Z"},{"id":"CVE-2026-67581","title":"On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay","details":"/cves/CVE-2026-67581.json","datePublished":"2026-08-19T17:20:09Z","dateUpdated":"2026-08-19T18:44:31Z"},{"id":"CVE-2026-73541","title":"Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain","details":"/cves/CVE-2026-73541.json","datePublished":"2026-08-19T17:20:00Z","dateUpdated":"2026-08-19T18:47:04Z"},{"id":"CVE-2026-73136","title":"Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay","details":"/cves/CVE-2026-73136.json","datePublished":"2026-08-19T17:19:52Z","dateUpdated":"2026-08-19T18:54:00Z"},{"id":"CVE-2026-73829","title":"Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race","details":"/cves/CVE-2026-73829.json","datePublished":"2026-08-19T17:19:43Z","dateUpdated":"2026-08-19T18:58:33Z"},{"id":"CVE-2026-43971","title":"Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1","details":"/cves/CVE-2026-43971.json","datePublished":"2026-08-18T09:01:53Z","dateUpdated":"2026-08-18T15:58:46Z"},{"id":"CVE-2026-67579","title":"Filter expression injection via forged keyset pagination cursor in Ash","details":"/cves/CVE-2026-67579.json","datePublished":"2026-08-12T20:04:42Z","dateUpdated":"2026-08-13T12:44:48Z"},{"id":"CVE-2026-64941","title":"Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR","details":"/cves/CVE-2026-64941.json","datePublished":"2026-08-10T11:05:14Z","dateUpdated":"2026-08-10T13:00:33Z"},{"id":"CVE-2026-70395","title":"Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash","details":"/cves/CVE-2026-70395.json","datePublished":"2026-08-09T18:17:07Z","dateUpdated":"2026-08-10T18:23:15Z"},{"id":"CVE-2026-69659","title":"Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset","details":"/cves/CVE-2026-69659.json","datePublished":"2026-08-09T18:01:32Z","dateUpdated":"2026-08-10T17:24:04Z"},{"id":"CVE-2026-67585","title":"Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation","details":"/cves/CVE-2026-67585.json","datePublished":"2026-08-07T16:42:22Z","dateUpdated":"2026-08-07T18:12:59Z"},{"id":"CVE-2026-66838","title":"SQL injection via the :comment option in Postgrex.stream/4","details":"/cves/CVE-2026-66838.json","datePublished":"2026-08-07T12:20:02Z","dateUpdated":"2026-08-07T15:12:12Z"},{"id":"CVE-2026-68750","title":"Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service","details":"/cves/CVE-2026-68750.json","datePublished":"2026-08-06T14:50:20Z","dateUpdated":"2026-08-19T11:47:34Z"},{"id":"CVE-2026-68749","title":"Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service","details":"/cves/CVE-2026-68749.json","datePublished":"2026-08-06T14:50:12Z","dateUpdated":"2026-08-19T11:48:20Z"},{"id":"CVE-2026-68747","title":"CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input","details":"/cves/CVE-2026-68747.json","datePublished":"2026-08-06T14:50:03Z","dateUpdated":"2026-08-19T11:50:10Z"},{"id":"CVE-2026-66829","title":"html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection","details":"/cves/CVE-2026-66829.json","datePublished":"2026-08-06T14:49:23Z","dateUpdated":"2026-08-19T11:50:39Z"},{"id":"CVE-2026-66370","title":"html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking","details":"/cves/CVE-2026-66370.json","datePublished":"2026-08-06T14:49:15Z","dateUpdated":"2026-08-19T11:51:08Z"},{"id":"CVE-2026-66843","title":"html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding","details":"/cves/CVE-2026-66843.json","datePublished":"2026-08-06T14:48:20Z","dateUpdated":"2026-08-19T11:51:46Z"},{"id":"CVE-2026-66885","title":"Livebook Teams identity callback lacks state binding, allowing login CSRF","details":"/cves/CVE-2026-66885.json","datePublished":"2026-08-05T19:44:23Z","dateUpdated":"2026-08-06T13:09:29Z"},{"id":"CVE-2026-66298","title":"JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts","details":"/cves/CVE-2026-66298.json","datePublished":"2026-08-05T19:44:11Z","dateUpdated":"2026-08-06T13:08:23Z"},{"id":"CVE-2026-66297","title":"Unescaped deployment environment variables in generated setup commands","details":"/cves/CVE-2026-66297.json","datePublished":"2026-08-05T19:43:58Z","dateUpdated":"2026-08-06T13:04:30Z"},{"id":"CVE-2026-66881","title":"Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download","details":"/cves/CVE-2026-66881.json","datePublished":"2026-08-05T19:43:48Z","dateUpdated":"2026-08-06T13:03:45Z"},{"id":"CVE-2026-68746","title":"Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access","details":"/cves/CVE-2026-68746.json","datePublished":"2026-08-05T19:43:38Z","dateUpdated":"2026-08-06T14:48:46Z"},{"id":"CVE-2026-66883","title":"Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup","details":"/cves/CVE-2026-66883.json","datePublished":"2026-08-04T11:46:05Z","dateUpdated":"2026-08-04T12:27:58Z"},{"id":"CVE-2026-66884","title":"Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection","details":"/cves/CVE-2026-66884.json","datePublished":"2026-08-04T11:45:49Z","dateUpdated":"2026-08-04T12:40:41Z"},{"id":"CVE-2026-66296","title":"Reflected XSS in oaskit's default HTML error handler","details":"/cves/CVE-2026-66296.json","datePublished":"2026-08-03T19:04:30Z","dateUpdated":"2026-08-03T19:50:27Z"},{"id":"CVE-2026-55734","title":"guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1","details":"/cves/CVE-2026-55734.json","datePublished":"2026-08-01T18:46:24Z","dateUpdated":"2026-08-03T16:49:59Z"},{"id":"CVE-2026-55733","title":"Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation","details":"/cves/CVE-2026-55733.json","datePublished":"2026-08-01T18:46:12Z","dateUpdated":"2026-08-03T16:50:53Z"},{"id":"CVE-2026-54894","title":"Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys","details":"/cves/CVE-2026-54894.json","datePublished":"2026-08-01T18:46:05Z","dateUpdated":"2026-08-03T17:49:54Z"},{"id":"CVE-2026-55735","title":"Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation","details":"/cves/CVE-2026-55735.json","datePublished":"2026-08-01T18:46:05Z","dateUpdated":"2026-08-03T19:30:07Z"},{"id":"CVE-2026-65636","title":"YAML injection via unescaped newlines in ymlr document comments","details":"/cves/CVE-2026-65636.json","datePublished":"2026-07-31T13:29:31Z","dateUpdated":"2026-08-01T04:18:38Z"},{"id":"CVE-2026-53431","title":"Boruta accepts expired JWT client assertions due to missing exp claim validation","details":"/cves/CVE-2026-53431.json","datePublished":"2026-07-30T14:17:27Z","dateUpdated":"2026-07-31T04:20:43Z"},{"id":"CVE-2026-65635","title":"Boruta dynamic client registration allows creation of over-privileged OAuth clients","details":"/cves/CVE-2026-65635.json","datePublished":"2026-07-30T14:17:02Z","dateUpdated":"2026-07-31T04:20:15Z"},{"id":"CVE-2026-54885","title":"Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching","details":"/cves/CVE-2026-54885.json","datePublished":"2026-07-30T14:16:43Z","dateUpdated":"2026-07-31T04:20:03Z"},{"id":"CVE-2026-59247","title":"Insufficient verification of Hex package metadata in Gleam","details":"/cves/CVE-2026-59247.json","datePublished":"2026-07-29T14:24:55Z","dateUpdated":"2026-07-30T04:15:30Z"},{"id":"CVE-2026-65624","title":"Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion","details":"/cves/CVE-2026-65624.json","datePublished":"2026-07-28T10:01:01Z","dateUpdated":"2026-07-29T04:17:22Z"},{"id":"CVE-2026-59248","title":"Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS","details":"/cves/CVE-2026-59248.json","datePublished":"2026-07-28T09:54:19Z","dateUpdated":"2026-07-29T04:18:17Z"},{"id":"CVE-2026-54890","title":"BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding","details":"/cves/CVE-2026-54890.json","datePublished":"2026-07-27T15:39:03Z","dateUpdated":"2026-07-28T09:55:08Z"},{"id":"CVE-2026-59251","title":"Denial of service via exponential certificate policy tree growth in path validation","details":"/cves/CVE-2026-59251.json","datePublished":"2026-07-27T15:30:47Z","dateUpdated":"2026-07-28T09:54:59Z"},{"id":"CVE-2026-59250","title":"Megaco flex scanner buffer overflow via oversized property parm name","details":"/cves/CVE-2026-59250.json","datePublished":"2026-07-27T15:25:03Z","dateUpdated":"2026-08-25T23:37:43Z"},{"id":"CVE-2026-55953","title":"TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication","details":"/cves/CVE-2026-55953.json","datePublished":"2026-07-27T15:21:29Z","dateUpdated":"2026-08-25T23:32:47Z"},{"id":"CVE-2026-55737","title":"Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder","details":"/cves/CVE-2026-55737.json","datePublished":"2026-07-27T15:13:54Z","dateUpdated":"2026-07-28T09:55:26Z"},{"id":"CVE-2026-47078","title":"Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass","details":"/cves/CVE-2026-47078.json","datePublished":"2026-07-27T15:03:50Z","dateUpdated":"2026-07-28T09:53:55Z"},{"id":"CVE-2026-42792","title":"epmd permanent DoS via EMFILE on accept(2) in erts","details":"/cves/CVE-2026-42792.json","datePublished":"2026-07-27T14:58:24Z","dateUpdated":"2026-07-28T09:55:23Z"},{"id":"CVE-2026-58227","title":"TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain","details":"/cves/CVE-2026-58227.json","datePublished":"2026-07-27T14:39:44Z","dateUpdated":"2026-07-28T09:53:23Z"},{"id":"CVE-2026-65623","title":"Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit","details":"/cves/CVE-2026-65623.json","datePublished":"2026-07-24T16:32:24Z","dateUpdated":"2026-07-25T04:16:42Z"},{"id":"CVE-2026-59252","title":"Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain","details":"/cves/CVE-2026-59252.json","datePublished":"2026-07-17T10:11:54Z","dateUpdated":"2026-07-18T04:12:42Z"},{"id":"CVE-2026-59694","title":"Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment","details":"/cves/CVE-2026-59694.json","datePublished":"2026-07-17T10:11:49Z","dateUpdated":"2026-07-18T04:12:36Z"},{"id":"CVE-2026-59695","title":"Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain","details":"/cves/CVE-2026-59695.json","datePublished":"2026-07-17T10:11:43Z","dateUpdated":"2026-07-18T04:12:26Z"},{"id":"CVE-2026-59249","title":"Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections","details":"/cves/CVE-2026-59249.json","datePublished":"2026-07-16T11:39:29Z","dateUpdated":"2026-07-17T10:11:36Z"},{"id":"CVE-2026-55954","title":"Missing ID token claim validation in ueberauth_apple allows account takeover","details":"/cves/CVE-2026-55954.json","datePublished":"2026-07-14T15:08:26Z","dateUpdated":"2026-07-15T04:14:10Z"},{"id":"CVE-2026-59246","title":"Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory","details":"/cves/CVE-2026-59246.json","datePublished":"2026-07-14T08:37:04Z","dateUpdated":"2026-07-14T15:08:39Z"},{"id":"CVE-2026-58229","title":"Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS","details":"/cves/CVE-2026-58229.json","datePublished":"2026-07-14T08:36:54Z","dateUpdated":"2026-07-14T15:07:57Z"},{"id":"CVE-2026-58228","title":"Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>","details":"/cves/CVE-2026-58228.json","datePublished":"2026-07-13T18:04:30Z","dateUpdated":"2026-07-14T04:15:01Z"},{"id":"CVE-2026-56813","title":"Cookie attribute injection in Plug.Conn.Cookies.encode/2","details":"/cves/CVE-2026-56813.json","datePublished":"2026-07-10T12:51:08Z","dateUpdated":"2026-07-10T14:45:34Z"},{"id":"CVE-2026-56814","title":"Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)","details":"/cves/CVE-2026-56814.json","datePublished":"2026-07-10T11:14:35Z","dateUpdated":"2026-07-10T14:41:43Z"},{"id":"CVE-2026-58225","title":"SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service","details":"/cves/CVE-2026-58225.json","datePublished":"2026-07-10T10:51:46Z","dateUpdated":"2026-07-10T12:50:40Z"},{"id":"CVE-2026-56812","title":"Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff","details":"/cves/CVE-2026-56812.json","datePublished":"2026-07-07T15:22:46Z","dateUpdated":"2026-07-07T16:11:22Z"},{"id":"CVE-2026-56811","title":"Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service","details":"/cves/CVE-2026-56811.json","datePublished":"2026-07-07T15:09:57Z","dateUpdated":"2026-07-07T16:14:39Z"},{"id":"CVE-2026-54893","title":"Email-derived URL path injection in the Swoosh Microsoft Graph adapter","details":"/cves/CVE-2026-54893.json","datePublished":"2026-07-06T14:04:16Z","dateUpdated":"2026-07-07T04:32:26Z"},{"id":"CVE-2026-56810","title":"mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5","details":"/cves/CVE-2026-56810.json","datePublished":"2026-07-06T09:17:17Z","dateUpdated":"2026-07-07T04:32:36Z"},{"id":"CVE-2026-58226","title":"Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax","details":"/cves/CVE-2026-58226.json","datePublished":"2026-07-06T09:03:47Z","dateUpdated":"2026-07-06T14:04:14Z"},{"id":"CVE-2026-54891","title":"Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl","details":"/cves/CVE-2026-54891.json","datePublished":"2026-07-02T16:06:30Z","dateUpdated":"2026-08-25T23:31:41Z"},{"id":"CVE-2026-55950","title":"DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions","details":"/cves/CVE-2026-55950.json","datePublished":"2026-07-02T16:06:24Z","dateUpdated":"2026-07-24T14:14:42Z"},{"id":"CVE-2026-54886","title":"SSH SFTP server denial of service via extended channel data infinite loop","details":"/cves/CVE-2026-54886.json","datePublished":"2026-07-02T16:06:20Z","dateUpdated":"2026-07-24T14:14:32Z"},{"id":"CVE-2026-55952","title":"TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension","details":"/cves/CVE-2026-55952.json","datePublished":"2026-07-02T16:06:08Z","dateUpdated":"2026-07-24T14:14:09Z"},{"id":"CVE-2026-54887","title":"DTLS server cookie bypass during startup window due to empty initial cookie secret","details":"/cves/CVE-2026-54887.json","datePublished":"2026-07-02T16:06:04Z","dateUpdated":"2026-07-24T14:15:16Z"},{"id":"CVE-2026-53422","title":"SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root","details":"/cves/CVE-2026-53422.json","datePublished":"2026-07-02T16:06:03Z","dateUpdated":"2026-07-24T14:16:07Z"},{"id":"CVE-2026-53426","title":"Atom-table exhaustion denial-of-service via JSON parse_document in MDEx","details":"/cves/CVE-2026-53426.json","datePublished":"2026-06-29T19:11:32Z","dateUpdated":"2026-06-30T04:38:27Z"},{"id":"CVE-2026-54889","title":"Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)","details":"/cves/CVE-2026-54889.json","datePublished":"2026-06-29T19:10:49Z","dateUpdated":"2026-06-30T04:38:42Z"},{"id":"CVE-2026-54888","title":"Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex","details":"/cves/CVE-2026-54888.json","datePublished":"2026-06-29T19:10:38Z","dateUpdated":"2026-06-30T04:37:59Z"},{"id":"CVE-2026-53429","title":"Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service","details":"/cves/CVE-2026-53429.json","datePublished":"2026-06-29T19:07:16Z","dateUpdated":"2026-06-30T04:38:14Z"},{"id":"CVE-2026-53428","title":"Unbounded memory allocation in highlight_lines range expansion in mdex","details":"/cves/CVE-2026-53428.json","datePublished":"2026-06-29T18:52:36Z","dateUpdated":"2026-06-30T04:38:36Z"},{"id":"CVE-2026-53427","title":"Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute","details":"/cves/CVE-2026-53427.json","datePublished":"2026-06-29T18:50:17Z","dateUpdated":"2026-06-30T04:37:51Z"},{"id":"CVE-2026-55736","title":"Private action arguments can be set by user input in Ash","details":"/cves/CVE-2026-55736.json","datePublished":"2026-06-23T18:21:13Z","dateUpdated":"2026-07-10T04:34:23Z"},{"id":"CVE-2026-54892","title":"Plug: quadratic-time decoding of nested query/body parameters enables denial of service","details":"/cves/CVE-2026-54892.json","datePublished":"2026-06-23T12:31:12Z","dateUpdated":"2026-06-23T18:21:14Z"},{"id":"CVE-2026-48591","title":"Stored XSS via unescaped HTML attribute values in earmark","details":"/cves/CVE-2026-48591.json","datePublished":"2026-06-17T16:42:37Z","dateUpdated":"2026-06-18T04:45:59Z"},{"id":"CVE-2026-48853","title":"Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc","details":"/cves/CVE-2026-48853.json","datePublished":"2026-06-15T21:56:15Z","dateUpdated":"2026-06-17T04:47:30Z"},{"id":"CVE-2026-53430","title":"grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1","details":"/cves/CVE-2026-53430.json","datePublished":"2026-06-15T21:55:33Z","dateUpdated":"2026-06-17T04:46:39Z"},{"id":"CVE-2026-48599","title":"Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding","details":"/cves/CVE-2026-48599.json","datePublished":"2026-06-15T21:55:28Z","dateUpdated":"2026-06-17T04:46:32Z"},{"id":"CVE-2026-48854","title":"Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc","details":"/cves/CVE-2026-48854.json","datePublished":"2026-06-15T21:55:23Z","dateUpdated":"2026-06-17T04:46:27Z"},{"id":"CVE-2026-49757","title":"OAuth2/OIDC account takeover in AshAuthentication via email-based user matching","details":"/cves/CVE-2026-49757.json","datePublished":"2026-06-15T10:07:17Z","dateUpdated":"2026-06-15T14:14:37Z"},{"id":"CVE-2026-53423","title":"Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin","details":"/cves/CVE-2026-53423.json","datePublished":"2026-06-11T10:44:51Z","dateUpdated":"2026-06-12T04:45:33Z"},{"id":"CVE-2026-48856","title":"httpc leaks Authorization header to cross-origin redirect targets","details":"/cves/CVE-2026-48856.json","datePublished":"2026-06-10T14:41:51Z","dateUpdated":"2026-07-24T14:16:40Z"},{"id":"CVE-2026-48860","title":"Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist","details":"/cves/CVE-2026-48860.json","datePublished":"2026-06-10T14:35:49Z","dateUpdated":"2026-07-24T14:15:28Z"},{"id":"CVE-2026-48855","title":"SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured","details":"/cves/CVE-2026-48855.json","datePublished":"2026-06-10T14:35:49Z","dateUpdated":"2026-07-24T14:15:22Z"},{"id":"CVE-2026-48858","title":"ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks","details":"/cves/CVE-2026-48858.json","datePublished":"2026-06-10T14:35:45Z","dateUpdated":"2026-07-24T14:16:02Z"},{"id":"CVE-2026-48859","title":"SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration","details":"/cves/CVE-2026-48859.json","datePublished":"2026-06-10T14:35:43Z","dateUpdated":"2026-08-03T19:17:49Z"},{"id":"CVE-2026-49759","title":"Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash","details":"/cves/CVE-2026-49759.json","datePublished":"2026-06-10T14:35:38Z","dateUpdated":"2026-07-24T14:15:34Z"},{"id":"CVE-2026-49760","title":"Stack Buffer Overflow in ei_s_print_term at Very Large Integer","details":"/cves/CVE-2026-49760.json","datePublished":"2026-06-10T14:35:36Z","dateUpdated":"2026-07-24T14:15:41Z"},{"id":"CVE-2026-49762","title":"Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service","details":"/cves/CVE-2026-49762.json","datePublished":"2026-06-09T14:04:07Z","dateUpdated":"2026-06-10T04:43:08Z"},{"id":"CVE-2026-43966","title":"HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2","details":"/cves/CVE-2026-43966.json","datePublished":"2026-06-08T16:34:33Z","dateUpdated":"2026-06-09T04:38:15Z"},{"id":"CVE-2026-49755","title":"Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies","details":"/cves/CVE-2026-49755.json","datePublished":"2026-06-08T15:20:57Z","dateUpdated":"2026-06-08T17:14:08Z"},{"id":"CVE-2026-49756","title":"Multipart form-data header injection in Req via unescaped name/filename/content_type","details":"/cves/CVE-2026-49756.json","datePublished":"2026-06-08T15:20:24Z","dateUpdated":"2026-06-08T16:34:58Z"},{"id":"CVE-2026-43973","title":"gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion","details":"/cves/CVE-2026-43973.json","datePublished":"2026-06-08T14:12:42Z","dateUpdated":"2026-06-08T16:35:01Z"},{"id":"CVE-2026-43972","title":"gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection","details":"/cves/CVE-2026-43972.json","datePublished":"2026-06-08T14:12:38Z","dateUpdated":"2026-06-08T16:34:45Z"},{"id":"CVE-2026-43974","title":"gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM","details":"/cves/CVE-2026-43974.json","datePublished":"2026-06-08T14:12:36Z","dateUpdated":"2026-06-08T16:34:38Z"},{"id":"CVE-2026-48596","title":"CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection","details":"/cves/CVE-2026-48596.json","datePublished":"2026-06-02T19:09:31Z","dateUpdated":"2026-06-04T04:45:42Z"},{"id":"CVE-2026-48594","title":"Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression","details":"/cves/CVE-2026-48594.json","datePublished":"2026-06-02T19:08:49Z","dateUpdated":"2026-06-04T04:45:31Z"},{"id":"CVE-2026-48595","title":"Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects","details":"/cves/CVE-2026-48595.json","datePublished":"2026-06-02T19:08:48Z","dateUpdated":"2026-06-04T04:45:31Z"},{"id":"CVE-2026-48597","title":"Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint","details":"/cves/CVE-2026-48597.json","datePublished":"2026-06-02T19:08:40Z","dateUpdated":"2026-06-04T04:45:28Z"},{"id":"CVE-2026-48598","title":"CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection","details":"/cves/CVE-2026-48598.json","datePublished":"2026-06-02T19:08:19Z","dateUpdated":"2026-06-04T04:45:23Z"},{"id":"CVE-2026-49753","title":"HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing","details":"/cves/CVE-2026-49753.json","datePublished":"2026-06-02T14:15:17Z","dateUpdated":"2026-06-02T19:14:42Z"},{"id":"CVE-2026-49754","title":"HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation","details":"/cves/CVE-2026-49754.json","datePublished":"2026-06-02T14:15:14Z","dateUpdated":"2026-06-02T19:14:33Z"},{"id":"CVE-2026-48862","title":"Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency","details":"/cves/CVE-2026-48862.json","datePublished":"2026-06-02T14:15:10Z","dateUpdated":"2026-06-02T19:14:09Z"},{"id":"CVE-2026-48861","title":"CRLF injection in HTTP/1 request line via unvalidated method in Mint","details":"/cves/CVE-2026-48861.json","datePublished":"2026-06-02T14:15:09Z","dateUpdated":"2026-06-02T19:14:00Z"},{"id":"CVE-2026-42795","title":"Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root","details":"/cves/CVE-2026-42795.json","datePublished":"2026-06-02T13:41:39Z","dateUpdated":"2026-06-02T19:14:25Z"},{"id":"CVE-2026-32685","title":"Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write","details":"/cves/CVE-2026-32685.json","datePublished":"2026-06-02T13:41:37Z","dateUpdated":"2026-06-02T19:14:20Z"},{"id":"CVE-2026-43965","title":"Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion","details":"/cves/CVE-2026-43965.json","datePublished":"2026-06-02T13:41:37Z","dateUpdated":"2026-06-02T19:14:19Z"},{"id":"CVE-2026-47074","title":"ex_aws_sns SigningCertURL not validated in verify_message/1","details":"/cves/CVE-2026-47074.json","datePublished":"2026-05-28T09:05:54Z","dateUpdated":"2026-05-29T04:40:43Z"},{"id":"CVE-2026-42790","title":"nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification","details":"/cves/CVE-2026-42790.json","datePublished":"2026-05-27T15:09:01Z","dateUpdated":"2026-08-14T12:04:26Z"},{"id":"CVE-2026-42791","title":"OCSP responder certificate validity period not checked in public_key","details":"/cves/CVE-2026-42791.json","datePublished":"2026-05-27T12:23:13Z","dateUpdated":"2026-07-24T14:14:24Z"},{"id":"CVE-2026-42789","title":"Non-CA certificate accepted as intermediate issuer in public_key path validation","details":"/cves/CVE-2026-42789.json","datePublished":"2026-05-27T12:23:06Z","dateUpdated":"2026-08-14T12:04:41Z"},{"id":"CVE-2026-48592","title":"Missing authorization check on save-job event handler in oban_web","details":"/cves/CVE-2026-48592.json","datePublished":"2026-05-26T19:46:48Z","dateUpdated":"2026-05-27T15:41:23Z"},{"id":"CVE-2026-48593","title":"Unbounded range expansion in cron describe causes memory exhaustion in oban_web","details":"/cves/CVE-2026-48593.json","datePublished":"2026-05-26T19:46:43Z","dateUpdated":"2026-05-27T15:40:57Z"},{"id":"CVE-2026-47073","title":"Unbounded memory consumption in WebSocket client in hackney","details":"/cves/CVE-2026-47073.json","datePublished":"2026-05-25T14:00:49Z","dateUpdated":"2026-05-27T15:41:30Z"},{"id":"CVE-2026-47067","title":"Atom table exhaustion via unrecognized URL schemes in hackney","details":"/cves/CVE-2026-47067.json","datePublished":"2026-05-25T14:00:48Z","dateUpdated":"2026-05-27T15:41:27Z"},{"id":"CVE-2026-47072","title":"CRLF injection in WebSocket upgrade request in hackney","details":"/cves/CVE-2026-47072.json","datePublished":"2026-05-25T14:00:47Z","dateUpdated":"2026-05-27T15:41:24Z"},{"id":"CVE-2026-47076","title":"SSRF allowlist bypass via percent-encoded host in hackney","details":"/cves/CVE-2026-47076.json","datePublished":"2026-05-25T14:00:46Z","dateUpdated":"2026-05-27T15:41:17Z"},{"id":"CVE-2026-47070","title":"HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney","details":"/cves/CVE-2026-47070.json","datePublished":"2026-05-25T14:00:46Z","dateUpdated":"2026-05-27T15:41:16Z"},{"id":"CVE-2026-47075","title":"CR/LF injection in query parameter in hackney","details":"/cves/CVE-2026-47075.json","datePublished":"2026-05-25T14:00:45Z","dateUpdated":"2026-07-24T14:15:24Z"},{"id":"CVE-2026-47077","title":"Unbounded body accumulation in HTTP/3 response loop in hackney","details":"/cves/CVE-2026-47077.json","datePublished":"2026-05-25T14:00:42Z","dateUpdated":"2026-05-27T15:40:53Z"},{"id":"CVE-2026-47071","title":"SOCKS5 TLS upgrade ignores caller timeout in hackney","details":"/cves/CVE-2026-47071.json","datePublished":"2026-05-25T14:00:41Z","dateUpdated":"2026-05-27T15:40:48Z"},{"id":"CVE-2026-47066","title":"Infinite loop in Alt-Svc header parser in hackney","details":"/cves/CVE-2026-47066.json","datePublished":"2026-05-25T14:00:39Z","dateUpdated":"2026-05-27T15:40:41Z"},{"id":"CVE-2026-47069","title":"CRLF injection in cookie domain/path options in hackney","details":"/cves/CVE-2026-47069.json","datePublished":"2026-05-25T14:00:39Z","dateUpdated":"2026-05-27T15:40:38Z"},{"id":"CVE-2026-47068","title":"Cross-session PubSub topic injection via URL parameter in phoenix_storybook","details":"/cves/CVE-2026-47068.json","datePublished":"2026-05-20T13:35:33Z","dateUpdated":"2026-05-27T15:41:37Z"},{"id":"CVE-2026-8467","title":"Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground","details":"/cves/CVE-2026-8467.json","datePublished":"2026-05-20T13:35:29Z","dateUpdated":"2026-05-27T15:41:02Z"},{"id":"CVE-2026-8469","title":"Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook","details":"/cves/CVE-2026-8469.json","datePublished":"2026-05-20T13:35:27Z","dateUpdated":"2026-05-27T15:40:55Z"},{"id":"CVE-2026-8468","title":"Unbounded buffer accumulation in multipart header parsing causes denial of service in plug","details":"/cves/CVE-2026-8468.json","datePublished":"2026-05-14T10:29:51Z","dateUpdated":"2026-05-27T15:41:29Z"},{"id":"CVE-2026-43970","title":"Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","details":"/cves/CVE-2026-43970.json","datePublished":"2026-05-13T18:43:11Z","dateUpdated":"2026-05-15T04:33:30Z"},{"id":"CVE-2026-8466","title":"Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy","details":"/cves/CVE-2026-8466.json","datePublished":"2026-05-13T18:26:21Z","dateUpdated":"2026-05-14T04:30:32Z"},{"id":"CVE-2026-39806","title":"HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit","details":"/cves/CVE-2026-39806.json","datePublished":"2026-05-13T13:36:17Z","dateUpdated":"2026-05-27T15:41:42Z"},{"id":"CVE-2026-39803","title":"HTTP/1 chunked body reader ignores length cap in bandit","details":"/cves/CVE-2026-39803.json","datePublished":"2026-05-13T13:36:09Z","dateUpdated":"2026-05-27T15:40:37Z"},{"id":"CVE-2026-32687","title":"SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3","details":"/cves/CVE-2026-32687.json","datePublished":"2026-05-12T14:18:07Z","dateUpdated":"2026-07-24T14:16:18Z"},{"id":"CVE-2026-43968","title":"CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1","details":"/cves/CVE-2026-43968.json","datePublished":"2026-05-11T18:06:42Z","dateUpdated":"2026-05-12T12:11:43Z"},{"id":"CVE-2026-7790","title":"Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS","details":"/cves/CVE-2026-7790.json","datePublished":"2026-05-11T18:06:41Z","dateUpdated":"2026-05-26T19:46:42Z"},{"id":"CVE-2026-43969","title":"Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1","details":"/cves/CVE-2026-43969.json","datePublished":"2026-05-11T18:06:40Z","dateUpdated":"2026-08-18T11:26:01Z"},{"id":"CVE-2026-42793","title":"Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe","details":"/cves/CVE-2026-42793.json","datePublished":"2026-05-08T15:42:46Z","dateUpdated":"2026-05-09T12:41:41Z"},{"id":"CVE-2026-42794","title":"Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug","details":"/cves/CVE-2026-42794.json","datePublished":"2026-05-08T15:42:40Z","dateUpdated":"2026-05-16T10:21:31Z"},{"id":"CVE-2026-43967","title":"Quadratic fragment-name uniqueness check causes denial of service in absinthe","details":"/cves/CVE-2026-43967.json","datePublished":"2026-05-08T15:42:34Z","dateUpdated":"2026-05-09T04:18:14Z"},{"id":"CVE-2026-32686","title":"Unbounded exponent in decimal enables unauthenticated DoS","details":"/cves/CVE-2026-32686.json","datePublished":"2026-05-07T14:04:47Z","dateUpdated":"2026-05-27T15:40:44Z"},{"id":"CVE-2026-32689","title":"Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix","details":"/cves/CVE-2026-32689.json","datePublished":"2026-05-05T15:17:30Z","dateUpdated":"2026-05-07T04:25:07Z"},{"id":"CVE-2026-39805","title":"CL.CL HTTP request smuggling via duplicate Content-Length in bandit","details":"/cves/CVE-2026-39805.json","datePublished":"2026-05-01T20:34:29Z","dateUpdated":"2026-07-24T14:16:00Z"},{"id":"CVE-2026-39804","title":"WebSocket permessage-deflate inflate has no output-size cap in bandit","details":"/cves/CVE-2026-39804.json","datePublished":"2026-05-01T20:34:24Z","dateUpdated":"2026-05-27T15:41:26Z"},{"id":"CVE-2026-39807","title":"Client-supplied URI scheme trusted without transport verification in bandit","details":"/cves/CVE-2026-39807.json","datePublished":"2026-05-01T20:34:22Z","dateUpdated":"2026-05-27T15:41:35Z"},{"id":"CVE-2026-42786","title":"WebSocket fragmented message reassembly unbounded in bandit","details":"/cves/CVE-2026-42786.json","datePublished":"2026-05-01T20:34:17Z","dateUpdated":"2026-05-27T15:41:06Z"},{"id":"CVE-2026-42788","title":"HTTP/2 frame size limit checked after body is buffered in bandit","details":"/cves/CVE-2026-42788.json","datePublished":"2026-05-01T20:34:11Z","dateUpdated":"2026-05-27T15:40:29Z"},{"id":"CVE-2026-32148","title":"Lockfile checksums not verified in Hex allows dependency integrity bypass","details":"/cves/CVE-2026-32148.json","datePublished":"2026-04-30T18:17:03Z","dateUpdated":"2026-05-01T04:33:38Z"},{"id":"CVE-2026-32688","title":"Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy","details":"/cves/CVE-2026-32688.json","datePublished":"2026-04-27T13:45:35Z","dateUpdated":"2026-04-29T17:08:07Z"},{"id":"CVE-2026-32147","title":"SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT","details":"/cves/CVE-2026-32147.json","datePublished":"2026-04-21T12:01:20Z","dateUpdated":"2026-07-24T14:14:17Z"},{"id":"CVE-2026-32146","title":"Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification","details":"/cves/CVE-2026-32146.json","datePublished":"2026-04-11T12:59:22Z","dateUpdated":"2026-07-15T04:14:12Z"},{"id":"CVE-2026-28808","title":"ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)","details":"/cves/CVE-2026-28808.json","datePublished":"2026-04-07T12:28:16Z","dateUpdated":"2026-07-24T14:14:26Z"},{"id":"CVE-2026-32144","title":"OCSP designated-responder authorization bypass via missing signature verification","details":"/cves/CVE-2026-32144.json","datePublished":"2026-04-07T12:28:00Z","dateUpdated":"2026-07-24T14:14:52Z"},{"id":"CVE-2026-28810","title":"Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver","details":"/cves/CVE-2026-28810.json","datePublished":"2026-04-07T07:50:11Z","dateUpdated":"2026-07-24T14:16:14Z"},{"id":"CVE-2026-32145","title":"Multipart form body parser bypasses body size limits in wisp","details":"/cves/CVE-2026-32145.json","datePublished":"2026-04-02T10:30:47Z","dateUpdated":"2026-04-07T04:07:10Z"},{"id":"CVE-2026-28809","title":"XXE in esaml SAML library allows local file read and potential SSRF","details":"/cves/CVE-2026-28809.json","datePublished":"2026-03-23T10:09:29Z","dateUpdated":"2026-07-24T14:14:51Z"},{"id":"CVE-2026-23940","title":"Denial of Service via Oversized Package Upload","details":"/cves/CVE-2026-23940.json","datePublished":"2026-03-13T16:07:53Z","dateUpdated":"2026-07-24T14:14:31Z"},{"id":"CVE-2026-23941","title":"Request smuggling via first-wins Content-Length parsing in inets httpd","details":"/cves/CVE-2026-23941.json","datePublished":"2026-03-13T09:11:58Z","dateUpdated":"2026-07-24T14:15:30Z"},{"id":"CVE-2026-23943","title":"Pre-auth SSH DoS via unbounded zlib inflate","details":"/cves/CVE-2026-23943.json","datePublished":"2026-03-13T09:11:57Z","dateUpdated":"2026-07-24T14:15:38Z"},{"id":"CVE-2026-23942","title":"SFTP root escape via component-agnostic prefix check in ssh_sftpd","details":"/cves/CVE-2026-23942.json","datePublished":"2026-03-13T09:11:56Z","dateUpdated":"2026-07-24T14:16:12Z"},{"id":"CVE-2026-28807","title":"Path Traversal in wisp.serve_static allows arbitrary file read","details":"/cves/CVE-2026-28807.json","datePublished":"2026-03-10T21:34:47Z","dateUpdated":"2026-04-06T16:44:07Z"},{"id":"CVE-2026-28806","title":"Improper authorization in device bulk actions and device update API allows cross-organization device control","details":"/cves/CVE-2026-28806.json","datePublished":"2026-03-10T21:30:58Z","dateUpdated":"2026-05-27T15:41:33Z"},{"id":"CVE-2026-21622","title":"Password Reset Tokens Do Not Expire","details":"/cves/CVE-2026-21622.json","datePublished":"2026-03-05T21:18:03Z","dateUpdated":"2026-04-21T04:15:20Z"},{"id":"CVE-2026-21621","title":"Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access","details":"/cves/CVE-2026-21621.json","datePublished":"2026-03-05T19:20:05Z","dateUpdated":"2026-04-06T16:44:09Z"},{"id":"CVE-2026-21619","title":"Unsafe Deserialization of Erlang Terms in hex_core","details":"/cves/CVE-2026-21619.json","datePublished":"2026-02-27T17:57:11Z","dateUpdated":"2026-05-27T15:40:33Z"},{"id":"CVE-2026-23939","title":"Path Traversal in Local File Store Backend","details":"/cves/CVE-2026-23939.json","datePublished":"2026-02-26T19:41:18Z","dateUpdated":"2026-04-07T14:38:03Z"},{"id":"CVE-2026-21620","title":"TFTP Path Traversal","details":"/cves/CVE-2026-21620.json","datePublished":"2026-02-20T10:57:08Z","dateUpdated":"2026-07-24T14:16:25Z"},{"id":"CVE-2026-21618","title":"Cross-site scripting (XSS) in OAuth Device Authorization screen","details":"/cves/CVE-2026-21618.json","datePublished":"2026-01-19T14:22:46Z","dateUpdated":"2026-07-24T14:16:04Z"},{"id":"CVE-2025-48044","title":"Authorization bypass when bypass policy condition evaluates to true","details":"/cves/CVE-2025-48044.json","datePublished":"2025-10-17T13:52:53Z","dateUpdated":"2026-07-24T14:13:58Z"},{"id":"CVE-2025-48043","title":"Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization","details":"/cves/CVE-2025-48043.json","datePublished":"2025-10-10T15:57:29Z","dateUpdated":"2026-07-24T14:14:08Z"},{"id":"CVE-2025-48041","title":"SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles","details":"/cves/CVE-2025-48041.json","datePublished":"2025-09-11T08:14:20Z","dateUpdated":"2026-07-24T14:14:04Z"},{"id":"CVE-2025-48040","title":"Malicious Key Exchange Messages may Lead to Excessive Resource Consumption","details":"/cves/CVE-2025-48040.json","datePublished":"2025-09-11T08:14:19Z","dateUpdated":"2026-07-24T14:14:06Z"},{"id":"CVE-2025-48039","title":"Unverified Paths can Cause Excessive Use of System Resources","details":"/cves/CVE-2025-48039.json","datePublished":"2025-09-11T08:13:36Z","dateUpdated":"2026-07-24T14:13:56Z"},{"id":"CVE-2025-48038","title":"Unverified File Handles can Cause Excessive Use of System Resources","details":"/cves/CVE-2025-48038.json","datePublished":"2025-09-11T08:13:04Z","dateUpdated":"2026-07-24T14:14:01Z"},{"id":"CVE-2025-48042","title":"Before action hooks may execute in certain scenarios despite a request being forbidden","details":"/cves/CVE-2025-48042.json","datePublished":"2025-09-07T16:01:01Z","dateUpdated":"2026-07-24T14:14:03Z"},{"id":"CVE-2025-4754","title":"Missing Session Revocation on Logout in ash_authentication_phoenix","details":"/cves/CVE-2025-4754.json","datePublished":"2025-06-17T14:31:37Z","dateUpdated":"2026-07-24T14:13:59Z"},{"id":"CVE-2025-4748","title":"Absolute path traversal in zip:unzip/1,2","details":"/cves/CVE-2025-4748.json","datePublished":"2025-06-16T11:00:54Z","dateUpdated":"2026-07-24T14:13:54Z"}]