Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-47070 HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney M 6.0 2026-05-25
CVE-2026-47075 CR/LF injection in query parameter in hackney M 6.8 2026-05-25
CVE-2026-47077 Unbounded body accumulation in HTTP/3 response loop in hackney H 8.2 2026-05-25
CVE-2026-47071 SOCKS5 TLS upgrade ignores caller timeout in hackney H 8.2 2026-05-25
CVE-2026-47066 Infinite loop in Alt-Svc header parser in hackney H 8.7 2026-05-25
CVE-2026-47069 CRLF injection in cookie domain/path options in hackney L 2.1 2026-05-25
CVE-2026-47068 Cross-session PubSub topic injection via URL parameter in phoenix_storybook L 2.3 2026-05-20
CVE-2026-8467 Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground C 9.5 2026-05-20
CVE-2026-8469 Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook H 8.2 2026-05-20
CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plug H 8.2 2026-05-14
CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame H 8.2 2026-05-13
CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy H 8.2 2026-05-13
CVE-2026-39806 HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit H 8.7 2026-05-13
CVE-2026-39803 HTTP/1 chunked body reader ignores length cap in bandit H 8.7 2026-05-13
CVE-2026-32687 SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3 H 7.5 2026-05-12
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 M 6.3 2026-05-11
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS H 8.7 2026-05-11
CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 L 2.1 2026-05-11
CVE-2026-42793 Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe H 8.2 2026-05-08
CVE-2026-42794 Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug L 2.3 2026-05-08
CVE-2026-43967 Quadratic fragment-name uniqueness check causes denial of service in absinthe H 8.7 2026-05-08
CVE-2026-32686 Unbounded exponent in decimal enables unauthenticated DoS M 6.9 2026-05-07
CVE-2026-32689 Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix H 8.7 2026-05-05
CVE-2026-39805 CL.CL HTTP request smuggling via duplicate Content-Length in bandit M 6.3 2026-05-01
CVE-2026-39804 WebSocket permessage-deflate inflate has no output-size cap in bandit H 8.2 2026-05-01
25 per page · 183 CVEs
« Page of 8 »