Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-39803 HTTP/1 chunked body reader ignores length cap in bandit H 8.7 2026-05-13
CVE-2026-32687 SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3 H 7.5 2026-05-12
CVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1 M 6.3 2026-05-11
CVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS H 8.7 2026-05-11
CVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 L 2.1 2026-05-11
CVE-2026-42793 Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe H 8.2 2026-05-08
CVE-2026-42794 Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug L 2.3 2026-05-08
CVE-2026-43967 Quadratic fragment-name uniqueness check causes denial of service in absinthe H 8.7 2026-05-08
CVE-2026-32686 Unbounded exponent in decimal enables unauthenticated DoS M 6.9 2026-05-07
CVE-2026-32689 Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix H 8.7 2026-05-05
CVE-2026-39805 CL.CL HTTP request smuggling via duplicate Content-Length in bandit M 6.3 2026-05-01
CVE-2026-39804 WebSocket permessage-deflate inflate has no output-size cap in bandit H 8.2 2026-05-01
CVE-2026-39807 Client-supplied URI scheme trusted without transport verification in bandit M 6.3 2026-05-01
CVE-2026-42786 WebSocket fragmented message reassembly unbounded in bandit H 8.7 2026-05-01
CVE-2026-42788 HTTP/2 frame size limit checked after body is buffered in bandit M 6.9 2026-05-01
CVE-2026-32148 Lockfile checksums not verified in Hex allows dependency integrity bypass
Hex Mix Integration
H 8.9 2026-04-30
CVE-2026-32688 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy H 8.7 2026-04-27
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
Erlang / ssh
M 5.3 2026-04-21
CVE-2026-32146 Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification
Gleam
ghcr.io / gleam-lang/gleam
H 8.3 2026-04-11
CVE-2026-28808 ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)
Erlang
Erlang / inets
H 8.3 2026-04-07
CVE-2026-32144 OCSP designated-responder authorization bypass via missing signature verification
Erlang / public_key
Erlang / ssl
H 7.6 2026-04-07
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
Erlang / kernel
M 6.3 2026-04-07
CVE-2026-32145 Multipart form body parser bypasses body size limits in wisp H 8.7 2026-04-02
CVE-2026-28809 XXE in esaml SAML library allows local file read and potential SSRF M 6.3 2026-03-23
CVE-2026-23940 Denial of Service via Oversized Package Upload H 7.1 2026-03-13
25 per page · 320 CVEs
« Page of 13 »