hex incidents
Recent hex vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection
Reflected XSS in oaskit's default HTML error handler
Reflected XSS in oaskit's default HTML error handler
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
ex_aws_sns SigningCertURL not validated in verify_message/1
ex_aws_sns SigningCertURL not validated in verify_message/1
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
XXE in esaml SAML library allows local file read and potential SSRF
XXE in esaml SAML library allows local file read and potential SSRF
Tooling for hex
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.