hex incidents
Recent hex vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
AshAi aggregate tool can read field-policy-protected fields
AshAi aggregate tool can read field-policy-protected fields
AshLua eval read operations can read field-policy-protected fields via aggregates
AshLua eval read operations can read field-policy-protected fields via aggregates
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records
Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
Unescaped path parameters in AshTypescript generated TypeScript client allow request redirection
Ash.Reactor change step fails open, skipping a change when its where guard raises
Ash.Reactor change step fails open, skipping a change when its where guard raises
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing reads
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
ETS and Mnesia data layers overwrite an existing record on create instead of enforcing primary-key uniqueness
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under another
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
Ash.Filter.Runtime materializes a combinatorial cross-product over to-many relationships, exhausting memory
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.Decimal
Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
RPC error handler fails open in AshTypescript, disclosing unredacted errors
RPC error handler fails open in AshTypescript, disclosing unredacted errors
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persistent denial of service
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Ash.Type ignores outer array constraints on nested {:array, {:array, type}} inputs
Authorization-redacted field values disclosed through AshTypescript result normalization
Authorization-redacted field values disclosed through AshTypescript result normalization
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is unresolved, leaking scoped records
Route handler return value echoed into AshTypescript error response
Route handler return value echoed into AshTypescript error response
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
Unbounded atom creation from typed struct field names in AshTypescript field selector
Unbounded atom creation from typed struct field names in AshTypescript field selector
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
Match regex runs on over-length input in Ash.Type.String, enabling regex denial of service
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow async reads
Declared argument constraints not enforced on AshTypescript typed controller routes
Declared argument constraints not enforced on AshTypescript typed controller routes
AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)
AshAdmin LiveView events intern atoms from client input, exhausting the atom table (node DoS)
Stored XSS in AshAdmin relationship typeahead via unescaped label_field content
Stored XSS in AshAdmin relationship typeahead via unescaped label_field content
EEx template evaluation of prompt content in AshAi enables remote code execution
EEx template evaluation of prompt content in AshAi enables remote code execution
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle
AshAdmin composite primary key decoding accepts arbitrary fields, enabling a secret-attribute oracle
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
AshAi echoes raw tool exception messages into the conversation, disclosing internal details
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
Identity tool filter in AshAi accepts operator maps, allowing update or destroy of unidentified records
Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message
AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message
AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
Path traversal in AshAdmin file uploads via unsanitized client filename
Path traversal in AshAdmin file uploads via unsanitized client filename
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data
AshPhoenix FilterForm allows filtering across non-public relationships, disclosing private related data
JSON path injection via unescaped get_path segments in AshSqlite
JSON path injection via unescaped get_path segments in AshSqlite
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Job argument injection via :args overrides primary_key and tenant in AshOban
Job argument injection via :args overrides primary_key and tenant in AshOban
Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification
Broken access control in AshGraphql subscription batcher applies authorization suppression to only the first notification
Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service
Query-complexity limit bypass via first/last pagination arguments in AshGraphql enables denial of service
Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment
Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment
Unescaped backslash allows LIKE wildcard injection in AshSql string search
Unescaped backslash allows LIKE wildcard injection in AshSql string search
rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres
rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres
Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic
Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topic
Same-named aggregates with differing filters are conflated in AshSql
Same-named aggregates with differing filters are conflated in AshSql
Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names
Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names
Unbounded handle_error recursion enables denial of service in AshOban triggers
Unbounded handle_error recursion enables denial of service in AshOban triggers
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
Unsafe deserialization of decrypted terms enables node DoS in AshCloak
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
exists/2 predicate silently dropped on limited relationships with a parent() filter in AshSql
Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read
Cross-tenant subscription disclosure in AshGraphql authorizes notifications in memory without a tenant-scoped read
Doggo vulnerable to cross-site scripting via unescaped date field values
Doggo vulnerable to cross-site scripting via unescaped date field values
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
Reflected XSS in AshAuthentication confirmation and magic link interaction forms
Reflected XSS in AshAuthentication confirmation and magic link interaction forms
gRPC Erlang package's path bindings are overridable by query string and request body
gRPC Erlang package's path bindings are overridable by query string and request body
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Round-trip Corruption via Improper Entity Escaping in xml_builder
Round-trip Corruption via Improper Entity Escaping in xml_builder
CDATA Section Breakout via Unsanitised ]]> in xml_builder
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses
HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit
HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit
HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay
Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race
Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
membrane_mp4_plugin has an unauthenticated denial-of-service via BEAM atom table exhaustion
Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1
Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1
Filter expression injection via forged keyset pagination cursor in Ash
Filter expression injection via forged keyset pagination cursor in Ash
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset
SQL injection via the :comment option in Postgrex.stream/4
SQL injection via the :comment option in Postgrex.stream/4
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Livebook Teams identity callback lacks state binding, allowing login CSRF
Livebook Teams identity callback lacks state binding, allowing login CSRF
Unescaped deployment environment variables in generated setup commands
Unescaped deployment environment variables in generated setup commands
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Reflected XSS in oaskit's default HTML error handler
Reflected XSS in oaskit's default HTML error handler
Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation
Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation
Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys
Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys
guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1
Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation
Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounded atom creation
YAML injection via unescaped newlines in ymlr document comments
YAML injection via unescaped newlines in ymlr document comments
Boruta accepts expired JWT client assertions due to missing exp claim validation
Boruta accepts expired JWT client assertions due to missing exp claim validation
Boruta dynamic client registration allows creation of over-privileged OAuth clients
Boruta dynamic client registration allows creation of over-privileged OAuth clients
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
Cookie attribute injection in Plug.Conn.Cookies.encode/2
Cookie attribute injection in Plug.Conn.Cookies.encode/2
SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service
SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Email-derived URL path injection in the Swoosh Microsoft Graph adapter
Email-derived URL path injection in the Swoosh Microsoft Graph adapter
Unbounded memory allocation in highlight_lines range expansion in mdex
Unbounded memory allocation in highlight_lines range expansion in mdex
Atom-table exhaustion denial-of-service via JSON parse_document in MDEx
Atom-table exhaustion denial-of-service via JSON parse_document in MDEx
Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute
Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute
Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)
Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)
Private action arguments can be set by user input in Ash
Private action arguments can be set by user input in Ash
Stored XSS via unescaped HTML attribute values in earmark
Stored XSS via unescaped HTML attribute values in earmark
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding
Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding
Multipart form-data header injection in Req via unescaped name/filename/content_type
Multipart form-data header injection in Req via unescaped name/filename/content_type
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
ex_aws_sns SigningCertURL not validated in verify_message/1
ex_aws_sns SigningCertURL not validated in verify_message/1
Unbounded range expansion in cron describe causes memory exhaustion in oban_web
Unbounded range expansion in cron describe causes memory exhaustion in oban_web
Missing authorization check on save-job event handler in oban_web
Missing authorization check on save-job event handler in oban_web
Unbounded body accumulation in HTTP/3 response loop in hackney
Unbounded body accumulation in HTTP/3 response loop in hackney
Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook
Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS
SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3
SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug
Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug
Unbounded exponent in decimal enables unauthenticated DoS
Unbounded exponent in decimal enables unauthenticated DoS
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
WebSocket fragmented message reassembly unbounded in bandit
WebSocket fragmented message reassembly unbounded in bandit
Client-supplied URI scheme trusted without transport verification in bandit
Client-supplied URI scheme trusted without transport verification in bandit
WebSocket permessage-deflate inflate has no output-size cap in bandit
WebSocket permessage-deflate inflate has no output-size cap in bandit
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
Multipart form body parser bypasses body size limits in wisp
Multipart form body parser bypasses body size limits in wisp
XXE in esaml SAML library allows local file read and potential SSRF
XXE in esaml SAML library allows local file read and potential SSRF
Samly access control vulnerability
Samly access control vulnerability
Phoenix before 1.6.14 mishandles check_origin wildcarding
Phoenix before 1.6.14 mishandles check_origin wildcarding
XSS in HEEx class attributes
XSS in HEEx class attributes
Tooling for hex
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.