We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect
EEF CNA
Issued CVEs
Vulnerabilities assigned and published by the EEF CNA.
| CVE ID | Title | Packages | Severity | Published |
|---|---|---|---|---|
| CVE-2026-53431 | Boruta accepts expired JWT client assertions due to missing exp claim validation | C 9.1 | 2026-07-30 | |
| CVE-2026-65635 | Boruta dynamic client registration allows creation of over-privileged OAuth clients | H 8.3 | 2026-07-30 | |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | M 6.9 | 2026-07-30 | |
| CVE-2026-59247 | Insufficient verification of Hex package metadata in Gleam |
pkg:sid/gleam.run/gleam
pkg:oci/gleam
|
H 7.6 | 2026-07-29 |
| CVE-2026-65624 | Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion | M 6.9 | 2026-07-28 | |
| CVE-2026-59248 | Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS | H 8.7 | 2026-07-28 | |
| CVE-2026-54890 | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
pkg:otp/erts
|
H 8.2 | 2026-07-27 |
| CVE-2026-59251 | Denial of service via exponential certificate policy tree growth in path validation |
pkg:otp/public_key
|
H 8.7 | 2026-07-27 |
| CVE-2026-59250 | Megaco flex scanner buffer overflow via oversized property parm name |
pkg:otp/megaco
|
H 8.3 | 2026-07-27 |
| CVE-2026-55953 | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication |
pkg:otp/ssl
|
C 9.1 | 2026-07-27 |
| CVE-2026-55737 | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder |
pkg:otp/erts
|
M 5.1 | 2026-07-27 |
| CVE-2026-47078 | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass |
pkg:otp/stdlib
|
M 4.8 | 2026-07-27 |
| CVE-2026-42792 | epmd permanent DoS via EMFILE on accept(2) in erts |
pkg:otp/erts
|
M 6.3 | 2026-07-27 |
| CVE-2026-58227 | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain |
pkg:otp/ssl
|
H 8.7 | 2026-07-27 |
| CVE-2026-65623 | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit | H 8.7 | 2026-07-24 | |
| CVE-2026-59252 | Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain | H 8.2 | 2026-07-17 | |
| CVE-2026-59694 | Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment | H 8.3 | 2026-07-17 | |
| CVE-2026-59695 | Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain | H 8.3 | 2026-07-17 | |
| CVE-2026-59249 | Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections | M 6.3 | 2026-07-16 | |
| CVE-2026-55954 | Missing ID token claim validation in ueberauth_apple allows account takeover | C 9.1 | 2026-07-14 | |
| CVE-2026-59246 | Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory | M 6.3 | 2026-07-14 | |
| CVE-2026-58229 | Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS | H 8.2 | 2026-07-14 | |
| CVE-2026-58228 | Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link> | M 5.1 | 2026-07-13 | |
| CVE-2026-56813 | Cookie attribute injection in Plug.Conn.Cookies.encode/2 | L 2.1 | 2026-07-10 | |
| CVE-2026-56814 | Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) | M 6.9 | 2026-07-10 |
25 per page ·
146 CVEs