Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-39807 Client-supplied URI scheme trusted without transport verification in bandit M 6.3 2026-05-01
CVE-2026-42786 WebSocket fragmented message reassembly unbounded in bandit H 8.7 2026-05-01
CVE-2026-42788 HTTP/2 frame size limit checked after body is buffered in bandit M 6.9 2026-05-01
CVE-2026-32148 Lockfile checksums not verified in Hex allows dependency integrity bypass
Hex Mix Integration
H 8.9 2026-04-30
CVE-2026-32688 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy H 8.7 2026-04-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
Erlang / ssh
M 5.3 2026-04-21
CVE-2026-32146 Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
Gleam
ghcr.io / gleam-lang/gleam
H 8.3 2026-04-11
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
Erlang / inets
H 8.3 2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification
Erlang / public_key
Erlang / ssl
H 7.6 2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
Erlang / kernel
M 6.3 2026-04-07
CVE-2026-32145 Multipart form body parser bypasses body size limits in wisp H 8.7 2026-04-02
CVE-2026-28809 XXE in esaml SAML library allows local file read and potential SSRF M 6.3 2026-03-23
CVE-2026-23940 Denial of Service via Oversized Package Upload H 7.1 2026-03-13
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd
Erlang / inets
H 7.0 2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate
Erlang / ssh
M 6.9 2026-03-13
CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd
Erlang / ssh
M 5.3 2026-03-13
CVE-2026-28807 Path Traversal in wisp.serve_static allows arbitrary file read H 8.7 2026-03-10
CVE-2026-28806 Improper authorization in device bulk actions and device update API allows cross-organization device control
Nerves Hub
ghcr.io / nerves-hub/nerves-hub
C 9.4 2026-03-10
CVE-2026-21622 Password Reset Tokens Do Not Expire C 9.5 2026-03-05
CVE-2026-21621 Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access H 7.0 2026-03-05
CVE-2026-21619 Unsafe Deserialization of Erlang Terms in hex_core
Hex Mix Integration
rebar3
L 2.0 2026-02-27
CVE-2026-23939 Path Traversal in Local File Store Backend M 6.9 2026-02-26
CVE-2026-21620 TFTP Path Traversal
Erlang / inets
Erlang / tftp
L 2.3 2026-02-20
CVE-2026-21618 Cross-site scripting (XSS) in OAuth Device Authorization screen H 8.5 2026-01-19
CVE-2025-48044 Authorization bypass when bypass policy condition evaluates to true H 8.6 2025-10-17
25 per page · 183 CVEs
« Page of 8 »