Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-23941 Request smuggling via first-wins Content-Length parsing in inets httpd
Erlang / inets
H 7.0 2026-03-13
CVE-2026-23943 Pre-auth SSH DoS via unbounded zlib inflate
Erlang / ssh
M 6.9 2026-03-13
CVE-2026-23942 SFTP root escape via component-agnostic prefix check in ssh_sftpd
Erlang / ssh
M 5.3 2026-03-13
CVE-2026-28807 Path Traversal in wisp.serve_static allows arbitrary file read H 8.7 2026-03-10
CVE-2026-28806 Improper authorization in device bulk actions and device update API allows cross-organization device control
Nerves Hub
ghcr.io / nerves-hub/nerves-hub
C 9.4 2026-03-10
CVE-2026-21622 Password Reset Tokens Do Not Expire C 9.5 2026-03-05
CVE-2026-21621 Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access H 7.0 2026-03-05
CVE-2026-21619 Unsafe Deserialization of Erlang Terms in hex_core
Hex Mix Integration
rebar3
L 2.0 2026-02-27
CVE-2026-23939 Path Traversal in Local File Store Backend M 6.9 2026-02-26
CVE-2026-21620 TFTP Path Traversal
Erlang / inets
Erlang / tftp
L 2.3 2026-02-20
CVE-2026-21618 Cross-site scripting (XSS) in OAuth Device Authorization screen H 8.5 2026-01-19
CVE-2025-48044 Authorization bypass when bypass policy condition evaluates to true H 8.6 2025-10-17
CVE-2025-48043 Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization H 8.6 2025-10-10
CVE-2025-48041 SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
Erlang / ssh
H 7.1 2025-09-11
CVE-2025-48040 Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
Erlang / ssh
M 6.9 2025-09-11
CVE-2025-48039 Unverified Paths can Cause Excessive Use of System Resources
Erlang / ssh
M 5.3 2025-09-11
CVE-2025-48038 Unverified File Handles can Cause Excessive Use of System Resources
Erlang / ssh
M 5.3 2025-09-11
CVE-2025-48042 Before action hooks may execute in certain scenarios despite a request being forbidden H 7.1 2025-09-07
CVE-2025-4754 Missing Session Revocation on Logout in ash_authentication_phoenix L 2.3 2025-06-17
CVE-2025-4748 Absolute path traversal in zip:unzip/1,2
Erlang / stdlib
M 4.8 2025-06-16
25 per page · 320 CVEs
« Page of 13