Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-32685 Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write
Gleam
ghcr.io / gleam-lang/gleam
M 4.6 2026-06-02
CVE-2026-43965 Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion
Gleam
ghcr.io / gleam-lang/gleam
M 5.6 2026-06-02
CVE-2026-47074 ex_aws_sns SigningCertURL not validated in verify_message/1 H 8.7 2026-05-28
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
Erlang / public_key
H 7.6 2026-05-27
CVE-2026-42791 OCSP responder certificate validity period not checked in public_key
Erlang / public_key
M 6.3 2026-05-27
CVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validation
Erlang
Erlang / public_key
H 7.0 2026-05-27
CVE-2026-48592 Missing authorization check on save-job event handler in oban_web M 5.3 2026-05-26
CVE-2026-48593 Unbounded range expansion in cron describe causes memory exhaustion in oban_web M 5.9 2026-05-26
CVE-2026-47073 Unbounded memory consumption in WebSocket client in hackney H 8.7 2026-05-25
CVE-2026-47067 Atom table exhaustion via unrecognized URL schemes in hackney H 8.7 2026-05-25
CVE-2026-47072 CRLF injection in WebSocket upgrade request in hackney M 6.9 2026-05-25
CVE-2026-47076 SSRF allowlist bypass via percent-encoded host in hackney M 6.9 2026-05-25
CVE-2026-47070 HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney M 6.0 2026-05-25
CVE-2026-47075 CR/LF injection in query parameter in hackney M 6.8 2026-05-25
CVE-2026-47077 Unbounded body accumulation in HTTP/3 response loop in hackney H 8.2 2026-05-25
CVE-2026-47071 SOCKS5 TLS upgrade ignores caller timeout in hackney H 8.2 2026-05-25
CVE-2026-47066 Infinite loop in Alt-Svc header parser in hackney H 8.7 2026-05-25
CVE-2026-47069 CRLF injection in cookie domain/path options in hackney L 2.1 2026-05-25
CVE-2026-47068 Cross-session PubSub topic injection via URL parameter in phoenix_storybook L 2.3 2026-05-20
CVE-2026-8467 Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground C 9.5 2026-05-20
CVE-2026-8469 Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook H 8.2 2026-05-20
CVE-2026-8468 Unbounded buffer accumulation in multipart header parsing causes denial of service in plug H 8.2 2026-05-14
CVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame H 8.2 2026-05-13
CVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy H 8.2 2026-05-13
CVE-2026-39806 HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit H 8.7 2026-05-13
25 per page · 320 CVEs
« Page of 13 »