Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
Erlang / ssl
H 8.7 2026-07-27
CVE-2026-65623 Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit H 8.7 2026-07-24
CVE-2026-59252 Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain H 8.2 2026-07-17
CVE-2026-59694 Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment H 8.3 2026-07-17
CVE-2026-59695 Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain H 8.3 2026-07-17
CVE-2026-59249 Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections M 6.3 2026-07-16
CVE-2026-55954 Missing ID token claim validation in ueberauth_apple allows account takeover C 9.1 2026-07-14
CVE-2026-59246 Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory M 6.3 2026-07-14
CVE-2026-58229 Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS H 8.2 2026-07-14
CVE-2026-58228 Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> M 5.1 2026-07-13
CVE-2026-56813 Cookie attribute injection in Plug.Conn.Cookies.encode/2 L 2.1 2026-07-10
CVE-2026-56814 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) M 6.9 2026-07-10
CVE-2026-58225 SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service L 2.1 2026-07-10
CVE-2026-56812 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff M 6.3 2026-07-07
CVE-2026-56811 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service H 8.7 2026-07-07
CVE-2026-54893 Email-derived URL path injection in the Swoosh Microsoft Graph adapter L 2.1 2026-07-06
CVE-2026-56810 mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5 H 8.7 2026-07-06
CVE-2026-58226 Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax H 8.7 2026-07-06
CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
Erlang
Erlang / ssl
M 6.3 2026-07-02
CVE-2026-55950 DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions
Erlang / ssl
H 8.7 2026-07-02
CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop
Erlang / ssh
M 5.3 2026-07-02
CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
Erlang / ssl
H 8.2 2026-07-02
CVE-2026-54887 DTLS server cookie bypass during startup window due to empty initial cookie secret
Erlang / ssl
M 6.3 2026-07-02
CVE-2026-53422 SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root
Erlang / ssh
L 2.3 2026-07-02
CVE-2026-53426 Atom-table exhaustion denial-of-service via JSON parse_document in MDEx H 8.2 2026-06-29
25 per page · 183 CVEs
« Page of 8 »