[{"id":"CVE-2026-53431","title":"Boruta accepts expired JWT client assertions due to missing exp claim validation","details":"/cves/CVE-2026-53431.json","datePublished":"2026-07-30T14:17:27Z","dateUpdated":"2026-07-30T16:13:22Z"},{"id":"CVE-2026-65635","title":"Boruta dynamic client registration allows creation of over-privileged OAuth clients","details":"/cves/CVE-2026-65635.json","datePublished":"2026-07-30T14:17:02Z","dateUpdated":"2026-07-30T16:13:59Z"},{"id":"CVE-2026-54885","title":"Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching","details":"/cves/CVE-2026-54885.json","datePublished":"2026-07-30T14:16:43Z","dateUpdated":"2026-07-30T16:14:32Z"},{"id":"CVE-2026-59247","title":"Insufficient verification of Hex package metadata in Gleam","details":"/cves/CVE-2026-59247.json","datePublished":"2026-07-29T14:24:55Z","dateUpdated":"2026-07-30T04:15:30Z"},{"id":"CVE-2026-65624","title":"Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion","details":"/cves/CVE-2026-65624.json","datePublished":"2026-07-28T10:01:01Z","dateUpdated":"2026-07-29T04:17:22Z"},{"id":"CVE-2026-59248","title":"Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS","details":"/cves/CVE-2026-59248.json","datePublished":"2026-07-28T09:54:19Z","dateUpdated":"2026-07-29T04:18:17Z"},{"id":"CVE-2026-54890","title":"BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding","details":"/cves/CVE-2026-54890.json","datePublished":"2026-07-27T15:39:03Z","dateUpdated":"2026-07-28T09:55:08Z"},{"id":"CVE-2026-59251","title":"Denial of service via exponential certificate policy tree growth in path validation","details":"/cves/CVE-2026-59251.json","datePublished":"2026-07-27T15:30:47Z","dateUpdated":"2026-07-28T09:54:59Z"},{"id":"CVE-2026-59250","title":"Megaco flex scanner buffer overflow via oversized property parm name","details":"/cves/CVE-2026-59250.json","datePublished":"2026-07-27T15:25:03Z","dateUpdated":"2026-07-28T09:55:21Z"},{"id":"CVE-2026-55953","title":"TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication","details":"/cves/CVE-2026-55953.json","datePublished":"2026-07-27T15:21:29Z","dateUpdated":"2026-07-28T09:54:51Z"},{"id":"CVE-2026-55737","title":"Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder","details":"/cves/CVE-2026-55737.json","datePublished":"2026-07-27T15:13:54Z","dateUpdated":"2026-07-28T09:55:26Z"},{"id":"CVE-2026-47078","title":"Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass","details":"/cves/CVE-2026-47078.json","datePublished":"2026-07-27T15:03:50Z","dateUpdated":"2026-07-28T09:53:55Z"},{"id":"CVE-2026-42792","title":"epmd permanent DoS via EMFILE on accept(2) in erts","details":"/cves/CVE-2026-42792.json","datePublished":"2026-07-27T14:58:24Z","dateUpdated":"2026-07-28T09:55:23Z"},{"id":"CVE-2026-58227","title":"TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain","details":"/cves/CVE-2026-58227.json","datePublished":"2026-07-27T14:39:44Z","dateUpdated":"2026-07-28T09:53:23Z"},{"id":"CVE-2026-65623","title":"Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit","details":"/cves/CVE-2026-65623.json","datePublished":"2026-07-24T16:32:24Z","dateUpdated":"2026-07-25T04:16:42Z"},{"id":"CVE-2026-59252","title":"Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain","details":"/cves/CVE-2026-59252.json","datePublished":"2026-07-17T10:11:54Z","dateUpdated":"2026-07-18T04:12:42Z"},{"id":"CVE-2026-59694","title":"Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment","details":"/cves/CVE-2026-59694.json","datePublished":"2026-07-17T10:11:49Z","dateUpdated":"2026-07-18T04:12:36Z"},{"id":"CVE-2026-59695","title":"Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain","details":"/cves/CVE-2026-59695.json","datePublished":"2026-07-17T10:11:43Z","dateUpdated":"2026-07-18T04:12:26Z"},{"id":"CVE-2026-59249","title":"Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections","details":"/cves/CVE-2026-59249.json","datePublished":"2026-07-16T11:39:29Z","dateUpdated":"2026-07-17T10:11:36Z"},{"id":"CVE-2026-55954","title":"Missing ID token claim validation in ueberauth_apple allows account takeover","details":"/cves/CVE-2026-55954.json","datePublished":"2026-07-14T15:08:26Z","dateUpdated":"2026-07-15T04:14:10Z"},{"id":"CVE-2026-59246","title":"Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory","details":"/cves/CVE-2026-59246.json","datePublished":"2026-07-14T08:37:04Z","dateUpdated":"2026-07-14T15:08:39Z"},{"id":"CVE-2026-58229","title":"Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS","details":"/cves/CVE-2026-58229.json","datePublished":"2026-07-14T08:36:54Z","dateUpdated":"2026-07-14T15:07:57Z"},{"id":"CVE-2026-58228","title":"Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>","details":"/cves/CVE-2026-58228.json","datePublished":"2026-07-13T18:04:30Z","dateUpdated":"2026-07-14T04:15:01Z"},{"id":"CVE-2026-56813","title":"Cookie attribute injection in Plug.Conn.Cookies.encode/2","details":"/cves/CVE-2026-56813.json","datePublished":"2026-07-10T12:51:08Z","dateUpdated":"2026-07-10T14:45:34Z"},{"id":"CVE-2026-56814","title":"Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)","details":"/cves/CVE-2026-56814.json","datePublished":"2026-07-10T11:14:35Z","dateUpdated":"2026-07-10T14:41:43Z"},{"id":"CVE-2026-58225","title":"SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service","details":"/cves/CVE-2026-58225.json","datePublished":"2026-07-10T10:51:46Z","dateUpdated":"2026-07-10T12:50:40Z"},{"id":"CVE-2026-56812","title":"Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff","details":"/cves/CVE-2026-56812.json","datePublished":"2026-07-07T15:22:46Z","dateUpdated":"2026-07-07T16:11:22Z"},{"id":"CVE-2026-56811","title":"Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service","details":"/cves/CVE-2026-56811.json","datePublished":"2026-07-07T15:09:57Z","dateUpdated":"2026-07-07T16:14:39Z"},{"id":"CVE-2026-54893","title":"Email-derived URL path injection in the Swoosh Microsoft Graph adapter","details":"/cves/CVE-2026-54893.json","datePublished":"2026-07-06T14:04:16Z","dateUpdated":"2026-07-07T04:32:26Z"},{"id":"CVE-2026-56810","title":"mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5","details":"/cves/CVE-2026-56810.json","datePublished":"2026-07-06T09:17:17Z","dateUpdated":"2026-07-07T04:32:36Z"},{"id":"CVE-2026-58226","title":"Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax","details":"/cves/CVE-2026-58226.json","datePublished":"2026-07-06T09:03:47Z","dateUpdated":"2026-07-06T14:04:14Z"},{"id":"CVE-2026-54891","title":"Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl","details":"/cves/CVE-2026-54891.json","datePublished":"2026-07-02T16:06:30Z","dateUpdated":"2026-07-24T14:16:34Z"},{"id":"CVE-2026-55950","title":"DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions","details":"/cves/CVE-2026-55950.json","datePublished":"2026-07-02T16:06:24Z","dateUpdated":"2026-07-24T14:14:42Z"},{"id":"CVE-2026-54886","title":"SSH SFTP server denial of service via extended channel data infinite loop","details":"/cves/CVE-2026-54886.json","datePublished":"2026-07-02T16:06:20Z","dateUpdated":"2026-07-24T14:14:32Z"},{"id":"CVE-2026-55952","title":"TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension","details":"/cves/CVE-2026-55952.json","datePublished":"2026-07-02T16:06:08Z","dateUpdated":"2026-07-24T14:14:09Z"},{"id":"CVE-2026-54887","title":"DTLS server cookie bypass during startup window due to empty initial cookie secret","details":"/cves/CVE-2026-54887.json","datePublished":"2026-07-02T16:06:04Z","dateUpdated":"2026-07-24T14:15:16Z"},{"id":"CVE-2026-53422","title":"SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root","details":"/cves/CVE-2026-53422.json","datePublished":"2026-07-02T16:06:03Z","dateUpdated":"2026-07-24T14:16:07Z"},{"id":"CVE-2026-53426","title":"Atom-table exhaustion denial-of-service via JSON parse_document in MDEx","details":"/cves/CVE-2026-53426.json","datePublished":"2026-06-29T19:11:32Z","dateUpdated":"2026-06-30T04:38:27Z"},{"id":"CVE-2026-54889","title":"Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)","details":"/cves/CVE-2026-54889.json","datePublished":"2026-06-29T19:10:49Z","dateUpdated":"2026-06-30T04:38:42Z"},{"id":"CVE-2026-54888","title":"Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex","details":"/cves/CVE-2026-54888.json","datePublished":"2026-06-29T19:10:38Z","dateUpdated":"2026-06-30T04:37:59Z"},{"id":"CVE-2026-53429","title":"Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service","details":"/cves/CVE-2026-53429.json","datePublished":"2026-06-29T19:07:16Z","dateUpdated":"2026-06-30T04:38:14Z"},{"id":"CVE-2026-53428","title":"Unbounded memory allocation in highlight_lines range expansion in mdex","details":"/cves/CVE-2026-53428.json","datePublished":"2026-06-29T18:52:36Z","dateUpdated":"2026-06-30T04:38:36Z"},{"id":"CVE-2026-53427","title":"Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute","details":"/cves/CVE-2026-53427.json","datePublished":"2026-06-29T18:50:17Z","dateUpdated":"2026-06-30T04:37:51Z"},{"id":"CVE-2026-55736","title":"Private action arguments can be set by user input in Ash","details":"/cves/CVE-2026-55736.json","datePublished":"2026-06-23T18:21:13Z","dateUpdated":"2026-07-10T04:34:23Z"},{"id":"CVE-2026-54892","title":"Plug: quadratic-time decoding of nested query/body parameters enables denial of service","details":"/cves/CVE-2026-54892.json","datePublished":"2026-06-23T12:31:12Z","dateUpdated":"2026-06-23T18:21:14Z"},{"id":"CVE-2026-48591","title":"Stored XSS via unescaped HTML attribute values in earmark","details":"/cves/CVE-2026-48591.json","datePublished":"2026-06-17T16:42:37Z","dateUpdated":"2026-06-18T04:45:59Z"},{"id":"CVE-2026-48853","title":"Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc","details":"/cves/CVE-2026-48853.json","datePublished":"2026-06-15T21:56:15Z","dateUpdated":"2026-06-17T04:47:30Z"},{"id":"CVE-2026-53430","title":"grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1","details":"/cves/CVE-2026-53430.json","datePublished":"2026-06-15T21:55:33Z","dateUpdated":"2026-06-17T04:46:39Z"},{"id":"CVE-2026-48599","title":"Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding","details":"/cves/CVE-2026-48599.json","datePublished":"2026-06-15T21:55:28Z","dateUpdated":"2026-06-17T04:46:32Z"},{"id":"CVE-2026-48854","title":"Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc","details":"/cves/CVE-2026-48854.json","datePublished":"2026-06-15T21:55:23Z","dateUpdated":"2026-06-17T04:46:27Z"},{"id":"CVE-2026-49757","title":"OAuth2/OIDC account takeover in AshAuthentication via email-based user matching","details":"/cves/CVE-2026-49757.json","datePublished":"2026-06-15T10:07:17Z","dateUpdated":"2026-06-15T14:14:37Z"},{"id":"CVE-2026-53423","title":"Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin","details":"/cves/CVE-2026-53423.json","datePublished":"2026-06-11T10:44:51Z","dateUpdated":"2026-06-12T04:45:33Z"},{"id":"CVE-2026-48856","title":"httpc leaks Authorization header to cross-origin redirect targets","details":"/cves/CVE-2026-48856.json","datePublished":"2026-06-10T14:41:51Z","dateUpdated":"2026-07-24T14:16:40Z"},{"id":"CVE-2026-48860","title":"Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist","details":"/cves/CVE-2026-48860.json","datePublished":"2026-06-10T14:35:49Z","dateUpdated":"2026-07-24T14:15:28Z"},{"id":"CVE-2026-48855","title":"SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured","details":"/cves/CVE-2026-48855.json","datePublished":"2026-06-10T14:35:49Z","dateUpdated":"2026-07-24T14:15:22Z"},{"id":"CVE-2026-48858","title":"ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks","details":"/cves/CVE-2026-48858.json","datePublished":"2026-06-10T14:35:45Z","dateUpdated":"2026-07-24T14:16:02Z"},{"id":"CVE-2026-48859","title":"SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration","details":"/cves/CVE-2026-48859.json","datePublished":"2026-06-10T14:35:43Z","dateUpdated":"2026-07-24T14:16:11Z"},{"id":"CVE-2026-49759","title":"Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash","details":"/cves/CVE-2026-49759.json","datePublished":"2026-06-10T14:35:38Z","dateUpdated":"2026-07-24T14:15:34Z"},{"id":"CVE-2026-49760","title":"Stack Buffer Overflow in ei_s_print_term at Very Large Integer","details":"/cves/CVE-2026-49760.json","datePublished":"2026-06-10T14:35:36Z","dateUpdated":"2026-07-24T14:15:41Z"},{"id":"CVE-2026-49762","title":"Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service","details":"/cves/CVE-2026-49762.json","datePublished":"2026-06-09T14:04:07Z","dateUpdated":"2026-06-10T04:43:08Z"},{"id":"CVE-2026-43966","title":"HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2","details":"/cves/CVE-2026-43966.json","datePublished":"2026-06-08T16:34:33Z","dateUpdated":"2026-06-09T04:38:15Z"},{"id":"CVE-2026-49755","title":"Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies","details":"/cves/CVE-2026-49755.json","datePublished":"2026-06-08T15:20:57Z","dateUpdated":"2026-06-08T17:14:08Z"},{"id":"CVE-2026-49756","title":"Multipart form-data header injection in Req via unescaped name/filename/content_type","details":"/cves/CVE-2026-49756.json","datePublished":"2026-06-08T15:20:24Z","dateUpdated":"2026-06-08T16:34:58Z"},{"id":"CVE-2026-43973","title":"gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion","details":"/cves/CVE-2026-43973.json","datePublished":"2026-06-08T14:12:42Z","dateUpdated":"2026-06-08T16:35:01Z"},{"id":"CVE-2026-43972","title":"gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection","details":"/cves/CVE-2026-43972.json","datePublished":"2026-06-08T14:12:38Z","dateUpdated":"2026-06-08T16:34:45Z"},{"id":"CVE-2026-43974","title":"gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM","details":"/cves/CVE-2026-43974.json","datePublished":"2026-06-08T14:12:36Z","dateUpdated":"2026-06-08T16:34:38Z"},{"id":"CVE-2026-48596","title":"CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection","details":"/cves/CVE-2026-48596.json","datePublished":"2026-06-02T19:09:31Z","dateUpdated":"2026-06-04T04:45:42Z"},{"id":"CVE-2026-48594","title":"Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression","details":"/cves/CVE-2026-48594.json","datePublished":"2026-06-02T19:08:49Z","dateUpdated":"2026-06-04T04:45:31Z"},{"id":"CVE-2026-48595","title":"Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects","details":"/cves/CVE-2026-48595.json","datePublished":"2026-06-02T19:08:48Z","dateUpdated":"2026-06-04T04:45:31Z"},{"id":"CVE-2026-48597","title":"Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint","details":"/cves/CVE-2026-48597.json","datePublished":"2026-06-02T19:08:40Z","dateUpdated":"2026-06-04T04:45:28Z"},{"id":"CVE-2026-48598","title":"CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection","details":"/cves/CVE-2026-48598.json","datePublished":"2026-06-02T19:08:19Z","dateUpdated":"2026-06-04T04:45:23Z"},{"id":"CVE-2026-49753","title":"HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing","details":"/cves/CVE-2026-49753.json","datePublished":"2026-06-02T14:15:17Z","dateUpdated":"2026-06-02T19:14:42Z"},{"id":"CVE-2026-49754","title":"HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation","details":"/cves/CVE-2026-49754.json","datePublished":"2026-06-02T14:15:14Z","dateUpdated":"2026-06-02T19:14:33Z"},{"id":"CVE-2026-48862","title":"Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency","details":"/cves/CVE-2026-48862.json","datePublished":"2026-06-02T14:15:10Z","dateUpdated":"2026-06-02T19:14:09Z"},{"id":"CVE-2026-48861","title":"CRLF injection in HTTP/1 request line via unvalidated method in Mint","details":"/cves/CVE-2026-48861.json","datePublished":"2026-06-02T14:15:09Z","dateUpdated":"2026-06-02T19:14:00Z"},{"id":"CVE-2026-42795","title":"Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root","details":"/cves/CVE-2026-42795.json","datePublished":"2026-06-02T13:41:39Z","dateUpdated":"2026-06-02T19:14:25Z"},{"id":"CVE-2026-32685","title":"Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write","details":"/cves/CVE-2026-32685.json","datePublished":"2026-06-02T13:41:37Z","dateUpdated":"2026-06-02T19:14:20Z"},{"id":"CVE-2026-43965","title":"Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion","details":"/cves/CVE-2026-43965.json","datePublished":"2026-06-02T13:41:37Z","dateUpdated":"2026-06-02T19:14:19Z"},{"id":"CVE-2026-47074","title":"ex_aws_sns SigningCertURL not validated in verify_message/1","details":"/cves/CVE-2026-47074.json","datePublished":"2026-05-28T09:05:54Z","dateUpdated":"2026-05-29T04:40:43Z"},{"id":"CVE-2026-42790","title":"nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification","details":"/cves/CVE-2026-42790.json","datePublished":"2026-05-27T15:09:01Z","dateUpdated":"2026-07-24T14:16:36Z"},{"id":"CVE-2026-42791","title":"OCSP responder certificate validity period not checked in public_key","details":"/cves/CVE-2026-42791.json","datePublished":"2026-05-27T12:23:13Z","dateUpdated":"2026-07-24T14:14:24Z"},{"id":"CVE-2026-42789","title":"Non-CA certificate accepted as intermediate issuer in public_key path validation","details":"/cves/CVE-2026-42789.json","datePublished":"2026-05-27T12:23:06Z","dateUpdated":"2026-07-24T14:16:20Z"},{"id":"CVE-2026-48592","title":"Missing authorization check on save-job event handler in oban_web","details":"/cves/CVE-2026-48592.json","datePublished":"2026-05-26T19:46:48Z","dateUpdated":"2026-05-27T15:41:23Z"},{"id":"CVE-2026-48593","title":"Unbounded range expansion in cron describe causes memory exhaustion in oban_web","details":"/cves/CVE-2026-48593.json","datePublished":"2026-05-26T19:46:43Z","dateUpdated":"2026-05-27T15:40:57Z"},{"id":"CVE-2026-47073","title":"Unbounded memory consumption in WebSocket client in hackney","details":"/cves/CVE-2026-47073.json","datePublished":"2026-05-25T14:00:49Z","dateUpdated":"2026-05-27T15:41:30Z"},{"id":"CVE-2026-47067","title":"Atom table exhaustion via unrecognized URL schemes in hackney","details":"/cves/CVE-2026-47067.json","datePublished":"2026-05-25T14:00:48Z","dateUpdated":"2026-05-27T15:41:27Z"},{"id":"CVE-2026-47072","title":"CRLF injection in WebSocket upgrade request in hackney","details":"/cves/CVE-2026-47072.json","datePublished":"2026-05-25T14:00:47Z","dateUpdated":"2026-05-27T15:41:24Z"},{"id":"CVE-2026-47076","title":"SSRF allowlist bypass via percent-encoded host in hackney","details":"/cves/CVE-2026-47076.json","datePublished":"2026-05-25T14:00:46Z","dateUpdated":"2026-05-27T15:41:17Z"},{"id":"CVE-2026-47070","title":"HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect target in hackney","details":"/cves/CVE-2026-47070.json","datePublished":"2026-05-25T14:00:46Z","dateUpdated":"2026-05-27T15:41:16Z"},{"id":"CVE-2026-47075","title":"CR/LF injection in query parameter in hackney","details":"/cves/CVE-2026-47075.json","datePublished":"2026-05-25T14:00:45Z","dateUpdated":"2026-07-24T14:15:24Z"},{"id":"CVE-2026-47077","title":"Unbounded body accumulation in HTTP/3 response loop in hackney","details":"/cves/CVE-2026-47077.json","datePublished":"2026-05-25T14:00:42Z","dateUpdated":"2026-05-27T15:40:53Z"},{"id":"CVE-2026-47071","title":"SOCKS5 TLS upgrade ignores caller timeout in hackney","details":"/cves/CVE-2026-47071.json","datePublished":"2026-05-25T14:00:41Z","dateUpdated":"2026-05-27T15:40:48Z"},{"id":"CVE-2026-47066","title":"Infinite loop in Alt-Svc header parser in hackney","details":"/cves/CVE-2026-47066.json","datePublished":"2026-05-25T14:00:39Z","dateUpdated":"2026-05-27T15:40:41Z"},{"id":"CVE-2026-47069","title":"CRLF injection in cookie domain/path options in hackney","details":"/cves/CVE-2026-47069.json","datePublished":"2026-05-25T14:00:39Z","dateUpdated":"2026-05-27T15:40:38Z"},{"id":"CVE-2026-47068","title":"Cross-session PubSub topic injection via URL parameter in phoenix_storybook","details":"/cves/CVE-2026-47068.json","datePublished":"2026-05-20T13:35:33Z","dateUpdated":"2026-05-27T15:41:37Z"},{"id":"CVE-2026-8467","title":"Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground","details":"/cves/CVE-2026-8467.json","datePublished":"2026-05-20T13:35:29Z","dateUpdated":"2026-05-27T15:41:02Z"},{"id":"CVE-2026-8469","title":"Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook","details":"/cves/CVE-2026-8469.json","datePublished":"2026-05-20T13:35:27Z","dateUpdated":"2026-05-27T15:40:55Z"},{"id":"CVE-2026-8468","title":"Unbounded buffer accumulation in multipart header parsing causes denial of service in plug","details":"/cves/CVE-2026-8468.json","datePublished":"2026-05-14T10:29:51Z","dateUpdated":"2026-05-27T15:41:29Z"},{"id":"CVE-2026-43970","title":"Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame","details":"/cves/CVE-2026-43970.json","datePublished":"2026-05-13T18:43:11Z","dateUpdated":"2026-05-15T04:33:30Z"},{"id":"CVE-2026-8466","title":"Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy","details":"/cves/CVE-2026-8466.json","datePublished":"2026-05-13T18:26:21Z","dateUpdated":"2026-05-14T04:30:32Z"},{"id":"CVE-2026-39806","title":"HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit","details":"/cves/CVE-2026-39806.json","datePublished":"2026-05-13T13:36:17Z","dateUpdated":"2026-05-27T15:41:42Z"},{"id":"CVE-2026-39803","title":"HTTP/1 chunked body reader ignores length cap in bandit","details":"/cves/CVE-2026-39803.json","datePublished":"2026-05-13T13:36:09Z","dateUpdated":"2026-05-27T15:40:37Z"},{"id":"CVE-2026-32687","title":"SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3","details":"/cves/CVE-2026-32687.json","datePublished":"2026-05-12T14:18:07Z","dateUpdated":"2026-07-24T14:16:18Z"},{"id":"CVE-2026-43968","title":"CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1","details":"/cves/CVE-2026-43968.json","datePublished":"2026-05-11T18:06:42Z","dateUpdated":"2026-05-12T12:11:43Z"},{"id":"CVE-2026-7790","title":"Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS","details":"/cves/CVE-2026-7790.json","datePublished":"2026-05-11T18:06:41Z","dateUpdated":"2026-05-26T19:46:42Z"},{"id":"CVE-2026-43969","title":"Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1","details":"/cves/CVE-2026-43969.json","datePublished":"2026-05-11T18:06:40Z","dateUpdated":"2026-05-12T04:26:34Z"},{"id":"CVE-2026-42793","title":"Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe","details":"/cves/CVE-2026-42793.json","datePublished":"2026-05-08T15:42:46Z","dateUpdated":"2026-05-09T12:41:41Z"},{"id":"CVE-2026-42794","title":"Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug","details":"/cves/CVE-2026-42794.json","datePublished":"2026-05-08T15:42:40Z","dateUpdated":"2026-05-16T10:21:31Z"},{"id":"CVE-2026-43967","title":"Quadratic fragment-name uniqueness check causes denial of service in absinthe","details":"/cves/CVE-2026-43967.json","datePublished":"2026-05-08T15:42:34Z","dateUpdated":"2026-05-09T04:18:14Z"},{"id":"CVE-2026-32686","title":"Unbounded exponent in decimal enables unauthenticated DoS","details":"/cves/CVE-2026-32686.json","datePublished":"2026-05-07T14:04:47Z","dateUpdated":"2026-05-27T15:40:44Z"},{"id":"CVE-2026-32689","title":"Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix","details":"/cves/CVE-2026-32689.json","datePublished":"2026-05-05T15:17:30Z","dateUpdated":"2026-05-07T04:25:07Z"},{"id":"CVE-2026-39805","title":"CL.CL HTTP request smuggling via duplicate Content-Length in bandit","details":"/cves/CVE-2026-39805.json","datePublished":"2026-05-01T20:34:29Z","dateUpdated":"2026-07-24T14:16:00Z"},{"id":"CVE-2026-39804","title":"WebSocket permessage-deflate inflate has no output-size cap in bandit","details":"/cves/CVE-2026-39804.json","datePublished":"2026-05-01T20:34:24Z","dateUpdated":"2026-05-27T15:41:26Z"},{"id":"CVE-2026-39807","title":"Client-supplied URI scheme trusted without transport verification in bandit","details":"/cves/CVE-2026-39807.json","datePublished":"2026-05-01T20:34:22Z","dateUpdated":"2026-05-27T15:41:35Z"},{"id":"CVE-2026-42786","title":"WebSocket fragmented message reassembly unbounded in bandit","details":"/cves/CVE-2026-42786.json","datePublished":"2026-05-01T20:34:17Z","dateUpdated":"2026-05-27T15:41:06Z"},{"id":"CVE-2026-42788","title":"HTTP/2 frame size limit checked after body is buffered in bandit","details":"/cves/CVE-2026-42788.json","datePublished":"2026-05-01T20:34:11Z","dateUpdated":"2026-05-27T15:40:29Z"},{"id":"CVE-2026-32148","title":"Lockfile checksums not verified in Hex allows dependency integrity bypass","details":"/cves/CVE-2026-32148.json","datePublished":"2026-04-30T18:17:03Z","dateUpdated":"2026-05-01T04:33:38Z"},{"id":"CVE-2026-32688","title":"Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy","details":"/cves/CVE-2026-32688.json","datePublished":"2026-04-27T13:45:35Z","dateUpdated":"2026-04-29T17:08:07Z"},{"id":"CVE-2026-32147","title":"SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT","details":"/cves/CVE-2026-32147.json","datePublished":"2026-04-21T12:01:20Z","dateUpdated":"2026-07-24T14:14:17Z"},{"id":"CVE-2026-32146","title":"Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification","details":"/cves/CVE-2026-32146.json","datePublished":"2026-04-11T12:59:22Z","dateUpdated":"2026-07-15T04:14:12Z"},{"id":"CVE-2026-28808","title":"ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)","details":"/cves/CVE-2026-28808.json","datePublished":"2026-04-07T12:28:16Z","dateUpdated":"2026-07-24T14:14:26Z"},{"id":"CVE-2026-32144","title":"OCSP designated-responder authorization bypass via missing signature verification","details":"/cves/CVE-2026-32144.json","datePublished":"2026-04-07T12:28:00Z","dateUpdated":"2026-07-24T14:14:52Z"},{"id":"CVE-2026-28810","title":"Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver","details":"/cves/CVE-2026-28810.json","datePublished":"2026-04-07T07:50:11Z","dateUpdated":"2026-07-24T14:16:14Z"},{"id":"CVE-2026-32145","title":"Multipart form body parser bypasses body size limits in wisp","details":"/cves/CVE-2026-32145.json","datePublished":"2026-04-02T10:30:47Z","dateUpdated":"2026-04-07T04:07:10Z"},{"id":"CVE-2026-28809","title":"XXE in esaml SAML library allows local file read and potential SSRF","details":"/cves/CVE-2026-28809.json","datePublished":"2026-03-23T10:09:29Z","dateUpdated":"2026-07-24T14:14:51Z"},{"id":"CVE-2026-23940","title":"Denial of Service via Oversized Package Upload","details":"/cves/CVE-2026-23940.json","datePublished":"2026-03-13T16:07:53Z","dateUpdated":"2026-07-24T14:14:31Z"},{"id":"CVE-2026-23941","title":"Request smuggling via first-wins Content-Length parsing in inets httpd","details":"/cves/CVE-2026-23941.json","datePublished":"2026-03-13T09:11:58Z","dateUpdated":"2026-07-24T14:15:30Z"},{"id":"CVE-2026-23943","title":"Pre-auth SSH DoS via unbounded zlib inflate","details":"/cves/CVE-2026-23943.json","datePublished":"2026-03-13T09:11:57Z","dateUpdated":"2026-07-24T14:15:38Z"},{"id":"CVE-2026-23942","title":"SFTP root escape via component-agnostic prefix check in ssh_sftpd","details":"/cves/CVE-2026-23942.json","datePublished":"2026-03-13T09:11:56Z","dateUpdated":"2026-07-24T14:16:12Z"},{"id":"CVE-2026-28807","title":"Path Traversal in wisp.serve_static allows arbitrary file read","details":"/cves/CVE-2026-28807.json","datePublished":"2026-03-10T21:34:47Z","dateUpdated":"2026-04-06T16:44:07Z"},{"id":"CVE-2026-28806","title":"Improper authorization in device bulk actions and device update API allows cross-organization device control","details":"/cves/CVE-2026-28806.json","datePublished":"2026-03-10T21:30:58Z","dateUpdated":"2026-05-27T15:41:33Z"},{"id":"CVE-2026-21622","title":"Password Reset Tokens Do Not Expire","details":"/cves/CVE-2026-21622.json","datePublished":"2026-03-05T21:18:03Z","dateUpdated":"2026-04-21T04:15:20Z"},{"id":"CVE-2026-21621","title":"Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access","details":"/cves/CVE-2026-21621.json","datePublished":"2026-03-05T19:20:05Z","dateUpdated":"2026-04-06T16:44:09Z"},{"id":"CVE-2026-21619","title":"Unsafe Deserialization of Erlang Terms in hex_core","details":"/cves/CVE-2026-21619.json","datePublished":"2026-02-27T17:57:11Z","dateUpdated":"2026-05-27T15:40:33Z"},{"id":"CVE-2026-23939","title":"Path Traversal in Local File Store Backend","details":"/cves/CVE-2026-23939.json","datePublished":"2026-02-26T19:41:18Z","dateUpdated":"2026-04-07T14:38:03Z"},{"id":"CVE-2026-21620","title":"TFTP Path Traversal","details":"/cves/CVE-2026-21620.json","datePublished":"2026-02-20T10:57:08Z","dateUpdated":"2026-07-24T14:16:25Z"},{"id":"CVE-2026-21618","title":"Cross-site scripting (XSS) in OAuth Device Authorization screen","details":"/cves/CVE-2026-21618.json","datePublished":"2026-01-19T14:22:46Z","dateUpdated":"2026-07-24T14:16:04Z"},{"id":"CVE-2025-48044","title":"Authorization bypass when bypass policy condition evaluates to true","details":"/cves/CVE-2025-48044.json","datePublished":"2025-10-17T13:52:53Z","dateUpdated":"2026-07-24T14:13:58Z"},{"id":"CVE-2025-48043","title":"Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization","details":"/cves/CVE-2025-48043.json","datePublished":"2025-10-10T15:57:29Z","dateUpdated":"2026-07-24T14:14:08Z"},{"id":"CVE-2025-48041","title":"SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles","details":"/cves/CVE-2025-48041.json","datePublished":"2025-09-11T08:14:20Z","dateUpdated":"2026-07-24T14:14:04Z"},{"id":"CVE-2025-48040","title":"Malicious Key Exchange Messages may Lead to Excessive Resource Consumption","details":"/cves/CVE-2025-48040.json","datePublished":"2025-09-11T08:14:19Z","dateUpdated":"2026-07-24T14:14:06Z"},{"id":"CVE-2025-48039","title":"Unverified Paths can Cause Excessive Use of System Resources","details":"/cves/CVE-2025-48039.json","datePublished":"2025-09-11T08:13:36Z","dateUpdated":"2026-07-24T14:13:56Z"},{"id":"CVE-2025-48038","title":"Unverified File Handles can Cause Excessive Use of System Resources","details":"/cves/CVE-2025-48038.json","datePublished":"2025-09-11T08:13:04Z","dateUpdated":"2026-07-24T14:14:01Z"},{"id":"CVE-2025-48042","title":"Before action hooks may execute in certain scenarios despite a request being forbidden","details":"/cves/CVE-2025-48042.json","datePublished":"2025-09-07T16:01:01Z","dateUpdated":"2026-07-24T14:14:03Z"},{"id":"CVE-2025-4754","title":"Missing Session Revocation on Logout in ash_authentication_phoenix","details":"/cves/CVE-2025-4754.json","datePublished":"2025-06-17T14:31:37Z","dateUpdated":"2026-07-24T14:13:59Z"},{"id":"CVE-2025-4748","title":"Absolute path traversal in zip:unzip/1,2","details":"/cves/CVE-2025-4748.json","datePublished":"2025-06-16T11:00:54Z","dateUpdated":"2026-07-24T14:13:54Z"}]