Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-53423 Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin M 5.9 2026-06-11
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets
Erlang
Erlang / inets
H 7.1 2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
Erlang
Erlang / ssl
H 7.5 2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured
Erlang
Erlang / ssh
L 2.3 2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
Erlang / inets
Erlang / ftp
M 6.3 2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration
Erlang
Erlang / ssh
M 6.3 2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash
Erlang
Erlang / erts
H 8.8 2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer
Erlang
Erlang / erl_interface
M 6.9 2026-06-10
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service
Elixir
M 5.1 2026-06-09
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 M 6.3 2026-06-08
CVE-2026-49755 Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies H 8.2 2026-06-08
CVE-2026-49756 Multipart form-data header injection in Req via unescaped name/filename/content_type L 2.1 2026-06-08
CVE-2026-43973 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion H 8.7 2026-06-08
CVE-2026-43972 gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection M 6.3 2026-06-08
CVE-2026-43974 gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM H 8.7 2026-06-08
CVE-2026-48596 CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection L 2.1 2026-06-02
CVE-2026-48594 Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression H 8.2 2026-06-02
CVE-2026-48595 Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects H 8.2 2026-06-02
CVE-2026-48597 Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint H 8.2 2026-06-02
CVE-2026-48598 CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection L 2.1 2026-06-02
CVE-2026-49753 HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing M 6.3 2026-06-02
CVE-2026-49754 HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation H 8.2 2026-06-02
CVE-2026-48862 Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency H 8.2 2026-06-02
CVE-2026-48861 CRLF injection in HTTP/1 request line via unvalidated method in Mint L 2.1 2026-06-02
CVE-2026-42795 Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root
Gleam
ghcr.io / gleam-lang/gleam
M 5.1 2026-06-02
25 per page · 320 CVEs
« Page of 13 »