Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-64941 Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR L 2.1 2026-08-10
CVE-2026-70395 Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash L 2.1 2026-08-09
CVE-2026-69659 Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset M 5.9 2026-08-09
CVE-2026-67585 Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation H 8.7 2026-08-07
CVE-2026-66838 SQL injection via the :comment option in Postgrex.stream/4 M 5.9 2026-08-07
CVE-2026-68750 Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service H 8.2 2026-08-06
CVE-2026-68749 Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service H 8.2 2026-08-06
CVE-2026-68747 CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input L 2.3 2026-08-06
CVE-2026-66829 html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection L 2.3 2026-08-06
CVE-2026-66370 html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking M 4.8 2026-08-06
CVE-2026-66843 html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding L 2.3 2026-08-06
CVE-2026-66885 Livebook Teams identity callback lacks state binding, allowing login CSRF
ghcr.io / livebook-dev/livebook
M 6.8 2026-08-05
CVE-2026-66298 JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
ghcr.io / livebook-dev/livebook
H 8.6 2026-08-05
CVE-2026-66297 Unescaped deployment environment variables in generated setup commands
ghcr.io / livebook-dev/livebook
M 5.0 2026-08-05
CVE-2026-66881 Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
ghcr.io / livebook-dev/livebook
H 7.0 2026-08-05
CVE-2026-68746 Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
ghcr.io / livebook-dev/livebook
H 7.7 2026-08-05
CVE-2026-66883 Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup M 6.3 2026-08-04
CVE-2026-66884 Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection L 2.1 2026-08-04
CVE-2026-66296 Reflected XSS in oaskit's default HTML error handler M 5.1 2026-08-03
CVE-2026-55734 guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1 M 6.9 2026-08-01
CVE-2026-55733 Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation M 6.9 2026-08-01
CVE-2026-54894 Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys M 6.9 2026-08-01
CVE-2026-55735 Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation H 8.2 2026-08-01
CVE-2026-65636 YAML injection via unescaped newlines in ymlr document comments L 2.1 2026-07-31
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation C 9.1 2026-07-30
25 per page · 320 CVEs
« Page of 13 »