Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-73812 inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-73276 inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-66357 inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-59696 uri_string does not bound the port component of a URI before integer conversion
Erlang
pkg:otp/stdlib
M 6.9 2026-09-01
CVE-2026-55951 httpc memory exhaustion via unbounded response header accumulation
Erlang
pkg:otp/inets
H 8.2 2026-09-01
CVE-2026-71380 httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-71562 httpc does not bound server-supplied numeric header values before integer conversion
Erlang
pkg:otp/inets
M 6.3 2026-09-01
CVE-2026-70399 httpd does not enforce the documented default max_clients connection limit
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-82747 Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor M 5.9 2026-09-01
CVE-2026-82749 Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records M 5.9 2026-09-01
CVE-2026-82748 Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another L 2.1 2026-09-01
CVE-2026-82746 Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records M 5.9 2026-09-01
CVE-2026-82745 ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness M 5.9 2026-09-01
CVE-2026-82744 Ash.Reactor change step fails open, skipping a change when its where guard raises L 2.1 2026-09-01
CVE-2026-82743 Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads L 2.1 2026-09-01
CVE-2026-82742 Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory M 5.9 2026-09-01
CVE-2026-82741 Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion L 2.1 2026-09-01
CVE-2026-82740 Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs L 2.1 2026-09-01
CVE-2026-82739 Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error L 2.1 2026-09-01
CVE-2026-82738 Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service M 5.9 2026-09-01
CVE-2026-82737 Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads M 5.9 2026-09-01
CVE-2026-82736 Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass L 2.1 2026-09-01
CVE-2026-82735 Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service M 5.9 2026-09-01
CVE-2026-82734 Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal L 2.1 2026-09-01
CVE-2026-82731 Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection L 2.3 2026-09-01
25 per page · 283 CVEs
« Page of 12 »