Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-78038 Job argument injection via :args overrides primary_key and tenant in AshOban M 5.9 2026-08-30
CVE-2026-77846 JSON path injection via unescaped get_path segments in AshSqlite L 2.1 2026-08-30
CVE-2026-75759 Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc H 7.6 2026-08-30
CVE-2026-77831 Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking L 2.1 2026-08-30
CVE-2026-77970 Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions M 5.9 2026-08-30
CVE-2026-75847 Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail M 5.9 2026-08-30
CVE-2026-75758 Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir
Elixir
M 5.9 2026-08-28
CVE-2026-66353 Doggo vulnerable to cross-site scripting via unescaped date field values M 5.3 2026-08-27
CVE-2026-65633 Purpose-limited JWT accepted as full bearer authentication in AshAuthentication H 7.6 2026-08-25
CVE-2026-66882 Reflected XSS in AshAuthentication confirmation and magic link interaction forms L 2.1 2026-08-25
CVE-2026-75554 Explicit organization scopes survive token refresh after membership ends L 2.3 2026-08-24
CVE-2026-75542 OAuth token exchange grants repository scopes for organizations the principal cannot access H 8.3 2026-08-24
CVE-2026-47079 Round-trip Corruption via Improper Entity Escaping in xml_builder L 2.1 2026-08-21
CVE-2026-48590 Element and Attribute Names Injected Verbatim into XML Output in xml_builder L 2.1 2026-08-21
CVE-2026-47080 CDATA Section Breakout via Unsanitised ]]> in xml_builder L 2.1 2026-08-21
CVE-2026-75484 HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit M 6.9 2026-08-20
CVE-2026-74836 HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit H 8.7 2026-08-20
CVE-2026-53424 Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions C 9.1 2026-08-20
CVE-2026-53425 Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses H 7.6 2026-08-20
CVE-2026-67581 On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay H 8.7 2026-08-19
CVE-2026-73541 Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain H 8.3 2026-08-19
CVE-2026-73136 Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay H 8.2 2026-08-19
CVE-2026-73829 Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race M 6.3 2026-08-19
CVE-2026-43971 Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1 M 6.3 2026-08-18
CVE-2026-67579 Filter expression injection via forged keyset pagination cursor in Ash H 7.5 2026-08-12
25 per page · 320 CVEs
« Page of 13 »