Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-82751 Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning H 8.3 2026-09-06
CVE-2026-82752 Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length M 5.9 2026-09-05
CVE-2026-82728 Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS H 8.2 2026-09-04
CVE-2026-82729 Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS M 6.3 2026-09-04
CVE-2026-69664 httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-70409 eldap does not bound the port component of a referral URL before integer conversion
Erlang
pkg:otp/eldap
M 6.3 2026-09-01
CVE-2026-70405 snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
Erlang
pkg:otp/snmp
M 6.3 2026-09-01
CVE-2026-66835 httpd mod_auth directory protection bypassed by a doubled slash in the request path
Erlang
pkg:otp/inets
H 8.2 2026-09-01
CVE-2026-73270 httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
Erlang
pkg:otp/inets
H 8.2 2026-09-01
CVE-2026-75538 A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
Erlang
pkg:otp/erts
H 8.2 2026-09-01
CVE-2026-74994 inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Erlang
pkg:otp/inets
M 6.0 2026-09-01
CVE-2026-74835 inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Body Reception
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-73812 inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-73276 inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-66357 inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
Erlang
pkg:otp/inets
H 8.3 2026-09-01
CVE-2026-59696 uri_string does not bound the port component of a URI before integer conversion
Erlang
pkg:otp/stdlib
M 6.9 2026-09-01
CVE-2026-55951 httpc memory exhaustion via unbounded response header accumulation
Erlang
pkg:otp/inets
H 8.2 2026-09-01
CVE-2026-71380 httpd applies no timeout while receiving a request body, parking a worker on a stalled client
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-71562 httpc does not bound server-supplied numeric header values before integer conversion
Erlang
pkg:otp/inets
M 6.3 2026-09-01
CVE-2026-70399 httpd does not enforce the documented default max_clients connection limit
Erlang
pkg:otp/inets
H 8.7 2026-09-01
CVE-2026-82747 Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor M 5.9 2026-09-01
CVE-2026-82749 Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records M 5.9 2026-09-01
CVE-2026-82748 Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another L 2.1 2026-09-01
CVE-2026-82746 Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records M 5.9 2026-09-01
CVE-2026-82745 ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness M 5.9 2026-09-01
25 per page · 320 CVEs
« Page of 13 »