Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff M 6.3 2026-07-07
CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service H 8.7 2026-07-07
CVE-2026-54893 Email-derived URL path injection in the Swoosh Microsoft Graph adapter L 2.1 2026-07-06
CVE-2026-56810 mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5 H 8.7 2026-07-06
CVE-2026-58226 Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax H 8.7 2026-07-06
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
Erlang
Erlang / ssl
M 6.3 2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions
Erlang / ssl
H 8.7 2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop
Erlang / ssh
M 5.3 2026-07-02
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
Erlang / ssl
H 8.2 2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret
Erlang / ssl
M 6.3 2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root
Erlang / ssh
L 2.3 2026-07-02
CVE-2026-53426 Atom-table exhaustion denial-of-service via JSON parse_document in MDEx H 8.2 2026-06-29
CVE-2026-54889 Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS) M 5.1 2026-06-29
CVE-2026-54888 Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex M 6.9 2026-06-29
CVE-2026-53429 Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service M 6.9 2026-06-29
CVE-2026-53428 Unbounded memory allocation in highlight_lines range expansion in mdex M 6.9 2026-06-29
CVE-2026-53427 Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute L 2.3 2026-06-29
CVE-2026-55736 Private action arguments can be set by user input in Ash M 5.9 2026-06-23
CVE-2026-54892 Plug: quadratic-time decoding of nested query/body parameters enables denial of service H 8.7 2026-06-23
CVE-2026-48591 Stored XSS via unescaped HTML attribute values in earmark M 4.8 2026-06-17
CVE-2026-48853 Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc C 9.2 2026-06-15
CVE-2026-53430 grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 H 8.7 2026-06-15
CVE-2026-48599 Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding H 7.6 2026-06-15
CVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc H 8.7 2026-06-15
CVE-2026-49757 OAuth2/OIDC account takeover in AshAuthentication via email-based user matching C 9.2 2026-06-15
25 per page · 320 CVEs
« Page of 13 »