hex incidents
Recent hex vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Filter expression injection via forged keyset pagination cursor in Ash
Filter expression injection via forged keyset pagination cursor in Ash
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
SQL injection via the :comment option in Postgrex.stream/4
SQL injection via the :comment option in Postgrex.stream/4
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
Unescaped deployment environment variables in generated setup commands
Unescaped deployment environment variables in generated setup commands
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
Livebook Teams identity callback lacks state binding, allowing login CSRF
Livebook Teams identity callback lacks state binding, allowing login CSRF
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Reflected XSS in oaskit's default HTML error handler
Reflected XSS in oaskit's default HTML error handler
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
ex_aws_sns SigningCertURL not validated in verify_message/1
ex_aws_sns SigningCertURL not validated in verify_message/1
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
XXE in esaml SAML library allows local file read and potential SSRF
XXE in esaml SAML library allows local file read and potential SSRF
Tooling for hex
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.