Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-43973 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion H 8.7 2026-06-08
CVE-2026-43972 gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection M 6.3 2026-06-08
CVE-2026-43974 gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM H 8.7 2026-06-08
CVE-2026-48596 CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection L 2.1 2026-06-02
CVE-2026-48594 Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression H 8.2 2026-06-02
CVE-2026-48595 Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects H 8.2 2026-06-02
CVE-2026-48597 Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint H 8.2 2026-06-02
CVE-2026-48598 CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection L 2.1 2026-06-02
CVE-2026-49753 HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing M 6.3 2026-06-02
CVE-2026-49754 HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation H 8.2 2026-06-02
CVE-2026-48862 Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency H 8.2 2026-06-02
CVE-2026-48861 CRLF injection in HTTP/1 request line via unvalidated method in Mint L 2.1 2026-06-02
CVE-2026-42795 Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root
Gleam
ghcr.io / gleam-lang/gleam
M 5.1 2026-06-02
CVE-2026-32685 Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write
Gleam
ghcr.io / gleam-lang/gleam
M 4.6 2026-06-02
CVE-2026-43965 Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion
Gleam
ghcr.io / gleam-lang/gleam
M 5.6 2026-06-02
CVE-2026-47074 ex_aws_sns SigningCertURL not validated in verify_message/1 H 8.7 2026-05-28
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
Erlang / public_key
H 7.6 2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key
Erlang / public_key
M 6.3 2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation
Erlang / public_key
H 7.0 2026-05-27
CVE-2026-48592 Missing authorization check on save-job event handler in oban_web M 5.3 2026-05-26
CVE-2026-48593 Unbounded range expansion in cron describe causes memory exhaustion in oban_web M 5.9 2026-05-26
CVE-2026-47073 Unbounded memory consumption in WebSocket client in hackney H 8.7 2026-05-25
CVE-2026-47067 Atom table exhaustion via unrecognized URL schemes in hackney H 8.7 2026-05-25
CVE-2026-47072 CRLF injection in WebSocket upgrade request in hackney M 6.9 2026-05-25
CVE-2026-47076 SSRF allowlist bypass via percent-encoded host in hackney M 6.9 2026-05-25
25 per page · 183 CVEs
« Page of 8 »