Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94206
  • Hex/cloak
  • Hex/cloak_ecto
  • github.com/danielberkompas/cloak
  • github.com/danielberkompas/cloak_ecto
Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds 1 hour ago
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-95105
  • Hex/cloak
  • github.com/danielberkompas/cloak
Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping 1 hour ago
  • No fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-94201
  • Hex/ash
  • github.com/ash-project/ash
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash 14 hours ago
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-105641
  • github.com/makeplane/plane
Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 16 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-105640
  • github.com/makeplane/plane
Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 16 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105639
  • github.com/makeplane/plane
Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 16 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-105638
  • github.com/makeplane/plane
Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 16 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105637
  • github.com/makeplane/plane
Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 16 hours ago
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-105636
  • github.com/makeplane/plane
Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 16 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-105635
  • github.com/makeplane/plane
Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token 16 hours ago
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-105634
  • github.com/makeplane/plane
Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles 16 hours ago
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-105633
  • github.com/makeplane/plane
Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope 16 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-105632
  • github.com/makeplane/plane
Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects 16 hours ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-93323
  • github.com/moby/buildkit
Oversized Dockerfile or .dockerignore can exhaust buildkitd memory 16 hours ago
  • No fix available
  • Severity - 6.8 (Medium)
CVE-2026-105631
  • github.com/makeplane/plane
Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure 16 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-105630
  • github.com/makeplane/plane
Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover) 16 hours ago
  • Fix available
  • Severity - 8.7 (High)