Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94201
  • Hex/ash
  • github.com/ash-project/ash
Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash 12 hours ago
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-105641
  • github.com/makeplane/plane
Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 13 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-105640
  • github.com/makeplane/plane
Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 13 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105639
  • github.com/makeplane/plane
Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 13 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-105638
  • github.com/makeplane/plane
Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 13 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-105637
  • github.com/makeplane/plane
Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 13 hours ago
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-105636
  • github.com/makeplane/plane
Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 13 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-105635
  • github.com/makeplane/plane
Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token 13 hours ago
  • Fix available
  • Severity - 7.4 (High)
CVE-2026-105634
  • github.com/makeplane/plane
Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles 13 hours ago
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-105633
  • github.com/makeplane/plane
Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope 13 hours ago
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-105632
  • github.com/makeplane/plane
Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects 13 hours ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-93323
  • github.com/moby/buildkit
Oversized Dockerfile or .dockerignore can exhaust buildkitd memory 13 hours ago
  • No fix available
  • Severity - 6.8 (Medium)
CVE-2026-105631
  • github.com/makeplane/plane
Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure 13 hours ago
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-105630
  • github.com/makeplane/plane
Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover) 13 hours ago
  • Fix available
  • Severity - 8.7 (High)
CVE-2026-93322
  • github.com/moby/buildkit
Malformed MergeOp can crash the BuildKit daemon 13 hours ago
  • No fix available
  • Severity - 6.9 (Medium)
CVE-2026-105629
  • github.com/makeplane/plane
Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup 13 hours ago
  • Fix available
  • Severity - 7.1 (High)