hex
Security Advisories in hex
Low
1 day ago
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
hex
xml_builder
Medium
2 days ago
HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit
hex
bandit
High
2 days ago
HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit
hex
bandit
Critical
2 days ago
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
hex
samly
High
2 days ago
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
hex
samly
Moderate
4 days ago
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
hex
membrane_mp4_plugin
Medium
4 days ago
Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1
hex
cowlib
Low
12 days ago
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
hex
phoenix_live_view
Low
13 days ago
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
hex
ash
Medium
13 days ago
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
hex
ash
High
15 days ago
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
hex
absinthe_federation
High
16 days ago
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
hex
html_sanitize_ex
High
16 days ago
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
hex
html_sanitize_ex
Low
16 days ago
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
hex
html_sanitize_ex
Low
16 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
hex
html_sanitize_ex
Medium
16 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
hex
html_sanitize_ex
Low
16 days ago
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
hex
html_sanitize_ex
Medium
17 days ago
Livebook Teams identity callback lacks state binding, allowing login CSRF
hex
livebook
High
17 days ago
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
hex
livebook
Medium
17 days ago
Unescaped deployment environment variables in generated setup commands
hex
livebook
High
17 days ago
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
hex
livebook
High
17 days ago
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
hex
livebook
Medium
18 days ago
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
hex
oidcc_plug
Medium
21 days ago
guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
hex
guardian
Medium
21 days ago
Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation
hex
guardian
Medium
21 days ago
Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys
hex
guardian
High
21 days ago
Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation
hex
guardian
Critical
23 days ago
Boruta accepts expired JWT client assertions due to missing exp claim validation
hex
boruta
High
23 days ago
Boruta dynamic client registration allows creation of over-privileged OAuth clients
hex
boruta
Medium
23 days ago
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
hex
boruta
Moderate
24 days ago
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
hex
req
High
24 days ago
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
hex
req
Medium
25 days ago
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
hex
cowboy
High
25 days ago
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS
hex
cowlib
High
29 days ago
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
hex
bandit
High
about 1 month ago
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
hex
mpp
High
about 1 month ago
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
hex
mpp
High
about 1 month ago
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
hex
mpp
Medium
about 1 month ago
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
hex
mint
High
about 1 month ago
Protobuf: Unbounded recursion depth in embedded-message decoding
hex
protobuf
Critical
about 1 month ago
Missing ID token claim validation in ueberauth_apple allows account takeover
hex
ueberauth_apple
Medium
about 1 month ago
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
hex
mint
High
about 1 month ago
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
hex
mint
Medium
about 1 month ago
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
hex
phoenix_live_view
Medium
about 1 month ago
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
hex
plug
Low
about 1 month ago
SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service
hex
postgrex
Low
about 1 month ago
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
hex
tesla
High
about 1 month ago
Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering
hex
tesla
Low
about 1 month ago
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param`
hex
tesla
High
about 1 month ago
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
hex
mint
High
about 1 month ago
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
hex
mint
Low
about 1 month ago
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
hex
mint
Medium
about 2 months ago
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
hex, npm
phoenix
High
about 2 months ago
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
hex
phoenix
Low
about 2 months ago
Email-derived URL path injection in the Swoosh Microsoft Graph adapter
hex
swoosh
High
about 2 months ago
mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5
hex
mint
High
about 2 months ago
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
hex
hpax
Moderate
about 2 months ago
oban_web missing authorization check on `save-job` event handler
hex
oban_web
Moderate
about 2 months ago
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
hex
oban_web
Moderate
about 2 months ago
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
hex
rabbit_common
Moderate
about 2 months ago
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
hex
rabbit_common
High
about 2 months ago
Atom-table exhaustion denial-of-service via JSON parse_document in MDEx
hex
mdex
Medium
about 2 months ago
Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)
hex
mdex
Medium
about 2 months ago
Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex
hex
mdex, mdex_native
Medium
about 2 months ago
Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service
hex
mdex, mdex_native
Medium
about 2 months ago
Unbounded memory allocation in highlight_lines range expansion in mdex
hex
mdex, mdex_native
Low
about 2 months ago
Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute
hex
mdex, mdex_native
High
about 2 months ago
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
hex
ex_aws_sns
High
about 2 months ago
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
hex
hackney
Moderate
about 2 months ago
Hackney has CRLF / header injection in WebSocket upgrade request
hex
hackney
High
about 2 months ago
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
hex
hackney
Moderate
about 2 months ago
Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
hex
hackney
Moderate
about 2 months ago
Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
hex
hackney
Low
about 2 months ago
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
hex
hackney
High
about 2 months ago
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
hex
hackney
Critical
about 2 months ago
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
hex
relyra
High
2 months ago
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
hex
plug
Critical
2 months ago
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
hex
grpc
Filter by Severity
Filter by Package
hackney
22
bandit
17
mint
12
cowlib
11
ash
11
tesla
10
plug
8
mpp
7
gun
7
mdex
6
phoenix_storybook
6
phoenix
6
html_sanitize_ex
6
livebook
6
req
4
oban_web
4
mdex_native
4
absinthe
4
wisp
4
postgrex
4
guardian
4
rabbit_common
4
cowboy
4
grpc
4
xml_builder
3
ewe
3
boruta
3
ash_authentication
3
hex_core
3
earmark
2
samly
2
phoenix_live_view
2
plug_cowboy
2
pow
2
oidcc_plug
2
ex_aws_sns
2
ash_authentication_phoenix
2
decimal
2
absinthe_plug
2
phoenix_html
2
membrane_mp4_plugin
2
xain
1
MongooseIM
1
github.com/altcha-org/altcha-lib-go
1
altcha
1
swoosh
1
ex_webrtc
1
mtproto_proxy
1
sweet_xml
1
oidcc
1
hpax
1
ymlr
1
puppetlabs-rabbitmq
1
ecto
1
altcha
1
paginator
1
absinthe_federation
1
altcha-org/altcha
1
protobuf
1
phoenix_html
1
RabbitMQ
1
altcha
1
alchemist.vim
1
jose
1
esaml
1
ueberauth_apple
1
quic
1
oaskit
1
ecdsa-elixir
1
altcha-lib
1
Samly
1
ejabberd
1
nodejs
1
ash_postgres
1
pleroma
1
coherence
1
org.altcha:altcha
1
pow_assent
1
phoenix
1
relyra
1
Filter by Repository
https://github.com/benoitc/hackney
12
https://github.com/ash-project/ash
10
https://github.com/mtrudel/bandit
10
https://github.com/elixir-mint/mint
8
https://github.com/ZenHive/mpp
7
https://github.com/livebook-dev/livebook
6
https://github.com/rrrene/html_sanitize_ex
6
https://github.com/elixir-tesla/tesla
5
https://github.com/elixir-plug/plug
5
https://github.com/ninenines/cowlib
5
https://github.com/elixir-ecto/ecto
4
https://github.com/phoenixframework/phoenix
4
https://github.com/ueberauth/guardian
4
https://github.com/elixir-grpc/grpc
4
https://github.com/leandrocp/mdex_native
4
https://github.com/joshnuss/xml_builder
3
https://github.com/ninenines/cowboy
3
https://github.com/ninenines/gun
3
https://github.com/phenixdigital/phoenix_storybook
3
https://github.com/malach-it/boruta_auth
3
https://github.com/team-alembic/ash_authentication
3
https://github.com/oban-bg/oban_web
2
https://github.com/gleam-wisp/wisp
2
https://github.com/leandrocp/mdex
2
https://github.com/absinthe-graphql/absinthe
2
https://github.com/wojtekmach/req
2
https://github.com/erlef/oidcc_plug
2
https://github.com/team-alembic/ash_authentication_phoenix
2
https://github.com/hexpm/hex_core
2
https://github.com/phoenixframework/phoenix_html
2
https://github.com/phoenixframework/phoenix_live_view
2
https://github.com/P3ngu1nW/CVE_Request
1
https://github.com/elixir-mint/hpax
1
https://github.com/danschultzer/pow
1
https://github.com/duffelhq/paginator
1
https://github.com/ericmj/decimal
1
https://github.com/swoosh/swoosh
1
https://github.com/DivvyPayHQ/absinthe_federation
1
https://github.com/pow-auth/pow
1
https://github.com/esl/MongooseIM
1
https://github.com/lud/oaskit
1
https://github.com/erlef/cowlib
1
https://github.com/DrunkenShells/Disclosures
1
https://github.com/smpallen99/xain
1
https://github.com/ash-project/ash_postgres
1
https://github.com/dropbox/samly
1
https://github.com/starkbank/ecdsa-elixir
1
https://github.com/kphrx/pleroma
1
https://github.com/ex-aws/ex_aws_sns
1
https://github.com/tonini/alchemist-server
1
https://github.com/kbrw/sweet_xml
1
https://github.com/erlef/oidcc
1
https://github.com/pow-auth/pow_assent
1
https://github.com/processone/ejabberd
1
https://github.com/smpallen99/coherence
1
https://github.com/elixir-plug/plug_cowboy
1
https://github.com/membraneframework/membrane_mp4_plugin
1
https://github.com/rabbitmq/rabbitmq-server
1
https://github.com/ufirstgroup/ymlr
1
https://github.com/ueberauth/ueberauth_apple
1
https://github.com/absinthe-graphql/absinthe_plug
1