Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-86522 Log injection via an unescaped password reset identity in AshAuthentication M 6.3 2026-09-17
CVE-2026-81637 Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication L 2.3 2026-09-17
CVE-2026-82761 Magic link single-use tokens replayable via TOCTOU race in AshAuthentication C 9.1 2026-09-17
CVE-2026-82685 Confirmation token accepted on any record in AshAuthentication H 7.6 2026-09-17
CVE-2026-82760 Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in H 8.2 2026-09-17
CVE-2026-82759 Reversible IP address pseudonymisation in AshAuthentication audit log hash mode L 1.8 2026-09-17
CVE-2026-82723 Actor record with password digest stored in AshAuthentication audit log entries L 1.8 2026-09-17
CVE-2026-86338 Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle M 6.0 2026-09-16
CVE-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot M 6.3 2026-09-16
CVE-2026-89186 mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches M 6.3 2026-09-16
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts C 9.0 2026-09-15
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding C 9.0 2026-09-15
CVE-2026-78216 AshLua eval read operations can read field-policy-protected fields via aggregates M 6.0 2026-09-08
CVE-2026-78230 AshAi aggregate tool can read field-policy-protected fields M 6.0 2026-09-08
CVE-2026-82710 Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata L 2.3 2026-09-08
CVE-2026-82584 Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata L 2.3 2026-09-07
CVE-2026-82586 AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes H 8.2 2026-09-07
CVE-2026-81638 Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry L 2.1 2026-09-07
CVE-2026-82758 ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint M 6.3 2026-09-07
CVE-2026-82757 ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF M 6.3 2026-09-07
CVE-2026-82756 ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection M 6.3 2026-09-07
CVE-2026-82755 ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion M 6.3 2026-09-07
CVE-2026-82754 ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls M 6.3 2026-09-07
CVE-2026-82753 Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server H 8.2 2026-09-07
CVE-2026-82750 Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation H 8.3 2026-09-06
25 per page · 320 CVEs
« Page of 13 »