Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-66298 JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
ghcr.io / livebook-dev/livebook
H 8.6 2026-08-05
CVE-2026-66297 Unescaped deployment environment variables in generated setup commands
ghcr.io / livebook-dev/livebook
M 5.0 2026-08-05
CVE-2026-66881 Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
ghcr.io / livebook-dev/livebook
H 7.0 2026-08-05
CVE-2026-68746 Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
ghcr.io / livebook-dev/livebook
H 7.7 2026-08-05
CVE-2026-66883 Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup M 6.3 2026-08-04
CVE-2026-66884 Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection L 2.1 2026-08-04
CVE-2026-66296 Reflected XSS in oaskit's default HTML error handler M 5.1 2026-08-03
CVE-2026-55734 guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1 M 6.9 2026-08-01
CVE-2026-55733 Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation M 6.9 2026-08-01
CVE-2026-54894 Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys M 6.9 2026-08-01
CVE-2026-55735 Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation H 8.2 2026-08-01
CVE-2026-65636 YAML injection via unescaped newlines in ymlr document comments L 2.1 2026-07-31
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation C 9.1 2026-07-30
CVE-2026-65635 Boruta dynamic client registration allows creation of over-privileged OAuth clients H 8.3 2026-07-30
CVE-2026-54885 Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching M 6.9 2026-07-30
CVE-2026-59247 Insufficient verification of Hex package metadata in Gleam
Gleam
ghcr.io / gleam-lang/gleam
H 7.6 2026-07-29
CVE-2026-65624 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion M 6.9 2026-07-28
CVE-2026-59248 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS H 8.7 2026-07-28
CVE-2026-54890 BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
Erlang / erts
H 8.2 2026-07-27
CVE-2026-59251 Denial of service via exponential certificate policy tree growth in path validation
Erlang / public_key
H 8.7 2026-07-27
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name
Erlang / megaco
H 8.3 2026-07-27
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
Erlang
Erlang / ssl
C 9.1 2026-07-27
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
Erlang / erts
M 5.1 2026-07-27
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
Erlang / stdlib
M 4.8 2026-07-27
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts
Erlang / erts
M 6.3 2026-07-27
25 per page · 183 CVEs
« Page of 8 »