hex incidents

Recent hex vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNHex

Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup

Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup

1 day ago
UNKNOWNHex

Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection

Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection

1 day ago
UNKNOWNHex

Reflected XSS in oaskit's default HTML error handler

Reflected XSS in oaskit's default HTML error handler

2 days agoEPSS 0%
UNKNOWNHex

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

4 weeks agoEPSS 1%
UNKNOWNHex

grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1

grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1

1 month agoEPSS 0%
UNKNOWNHex

gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

1 month agoEPSS 0%
UNKNOWNHex

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

1 month agoEPSS 0%
UNKNOWNHex

HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

1 month agoEPSS 0%
UNKNOWNHex

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

1 month agoEPSS 0%
UNKNOWNHex

ex_aws_sns SigningCertURL not validated in verify_message/1

ex_aws_sns SigningCertURL not validated in verify_message/1

2 months agoEPSS 0%
UNKNOWNHex

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

2 months agoEPSS 0%
UNKNOWNHex

XXE in esaml SAML library allows local file read and potential SSRF

XXE in esaml SAML library allows local file read and potential SSRF

4 months agoEPSS 0%

Tooling for hex

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GoMavenNuGetPyPIRubyGemscrates.ionpm