hex incidents

Recent hex vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNHex

Filter expression injection via forged keyset pagination cursor in Ash

Filter expression injection via forged keyset pagination cursor in Ash

6 days ago
UNKNOWNHex

Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR

Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR

1 week ago
UNKNOWNHex

Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset

1 week ago
UNKNOWNHex

Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash

Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash

1 week ago
UNKNOWNHex

SQL injection via the :comment option in Postgrex.stream/4

SQL injection via the :comment option in Postgrex.stream/4

1 week ago
UNKNOWNHex

Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation

Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation

1 week ago
UNKNOWNHex

html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection

html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection

1 week ago
UNKNOWNHex

html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking

html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking

1 week ago
UNKNOWNHex

Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service

Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service

1 week ago
UNKNOWNHex

html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding

html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding

1 week ago
UNKNOWNHex

Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service

Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service

1 week ago
UNKNOWNHex

CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input

CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input

1 week ago
UNKNOWNHex

Unescaped deployment environment variables in generated setup commands

Unescaped deployment environment variables in generated setup commands

1 week ago
UNKNOWNHex

Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download

Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download

1 week ago
UNKNOWNHex

Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access

Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access

1 week ago
UNKNOWNHex

JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts

JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts

1 week ago
UNKNOWNHex

Livebook Teams identity callback lacks state binding, allowing login CSRF

Livebook Teams identity callback lacks state binding, allowing login CSRF

1 week ago
UNKNOWNHex

Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup

Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup

2 weeks ago
UNKNOWNHex

Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection

Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection

2 weeks ago
UNKNOWNHex

Reflected XSS in oaskit's default HTML error handler

Reflected XSS in oaskit's default HTML error handler

2 weeks agoEPSS 0%
UNKNOWNHex

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

1 month agoEPSS 1%
UNKNOWNHex

grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1

grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1

2 months agoEPSS 0%
UNKNOWNHex

gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM

2 months agoEPSS 0%
UNKNOWNHex

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

2 months agoEPSS 0%
UNKNOWNHex

HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

2 months agoEPSS 0%
UNKNOWNHex

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

2 months agoEPSS 0%
UNKNOWNHex

ex_aws_sns SigningCertURL not validated in verify_message/1

ex_aws_sns SigningCertURL not validated in verify_message/1

2 months agoEPSS 0%
MODERATEHex

Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS

Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS

3 months ago
UNKNOWNHex

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

3 months agoEPSS 0%
UNKNOWNHex

XXE in esaml SAML library allows local file read and potential SSRF

XXE in esaml SAML library allows local file read and potential SSRF

4 months agoEPSS 0%

Tooling for hex

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GoMavenNuGetPyPIRubyGemscrates.ionpm