Machine-readable: JSON · OSV · Atom · RSS

CVE ID Title Packages Severity Published
CVE-2026-54889 Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS) M 5.1 2026-06-29
CVE-2026-54888 Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex M 6.9 2026-06-29
CVE-2026-53429 Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service M 6.9 2026-06-29
CVE-2026-53428 Unbounded memory allocation in highlight_lines range expansion in mdex M 6.9 2026-06-29
CVE-2026-53427 Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute L 2.3 2026-06-29
CVE-2026-55736 Private action arguments can be set by user input in Ash M 5.9 2026-06-23
CVE-2026-54892 Plug: quadratic-time decoding of nested query/body parameters enables denial of service H 8.7 2026-06-23
CVE-2026-48591 Stored XSS via unescaped HTML attribute values in earmark M 4.8 2026-06-17
CVE-2026-48853 Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc C 9.2 2026-06-15
CVE-2026-53430 grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1 H 8.7 2026-06-15
CVE-2026-48599 Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding H 7.6 2026-06-15
CVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc H 8.7 2026-06-15
CVE-2026-49757 OAuth2/OIDC account takeover in AshAuthentication via email-based user matching C 9.2 2026-06-15
CVE-2026-53423 Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin M 5.9 2026-06-11
CVE-2026-48856 httpc leaks Authorization header to cross-origin redirect targets
Erlang / inets
H 7.1 2026-06-10
CVE-2026-48860 Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
Erlang / ssl
H 7.5 2026-06-10
CVE-2026-48855 SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured
Erlang / ssh
L 2.3 2026-06-10
CVE-2026-48858 ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks
Erlang / inets
Erlang / ftp
M 6.3 2026-06-10
CVE-2026-48859 SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration
Erlang
Erlang / ssh
M 6.3 2026-06-10
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash
Erlang / erts
H 8.8 2026-06-10
CVE-2026-49760 Stack Buffer Overflow in ei_s_print_term at Very Large Integer
Erlang / erl_interface
M 6.9 2026-06-10
CVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service
Elixir
M 5.1 2026-06-09
CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 M 6.3 2026-06-08
CVE-2026-49755 Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies H 8.2 2026-06-08
CVE-2026-49756 Multipart form-data header injection in Req via unescaped name/filename/content_type L 2.1 2026-06-08
25 per page · 183 CVEs
« Page of 8 »