Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-86698
  • github.com/hexpm/hexpm
Refresh tokens accepted as private repository credentials at the CDN 6 hours ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-87119
  • Hex/mpp
  • github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed 11 hours ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-89420
  • Hex/mpp
  • github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free 11 hours ago
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-65634
  • github.com/erlang/otp
Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder 13 hours ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-68956
  • github.com/erlang/otp
SSH daemon allocates unbounded idle session channels, bypassing max_channels 13 hours ago
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-89422
  • github.com/erlang/otp
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension 13 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
CVE-2026-93712
  • github.com/perldancer/dancer2
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler 21 hours ago
  • Fix available
CVE-2026-93711
  • github.com/perldancer/dancer2
Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array 21 hours ago
  • Fix available
CVE-2026-93710
  • github.com/perldancer/dancer2
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks 21 hours ago
  • Fix available
CVE-2026-93709
  • github.com/perldancer/dancer2
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler 21 hours ago
  • Fix available
OSV-2026-1314
  • OSS-Fuzz/net-snmp
  • github.com/net-snmp/net-snmp
Heap-buffer-overflow in vacm_getAccessEntry 22 hours ago
  • Fix available
CVE-2026-94627
  • github.com/vllm-project/vllm
vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision yesterday
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-94626
  • github.com/vllm-project/vllm
vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size yesterday
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-94625
  • github.com/vllm-project/vllm
vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Placeholders yesterday
  • No fix available
  • Severity - 6.9 (Medium)
CVE-2026-94624
  • github.com/vllm-project/vllm
vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions yesterday
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-94623
  • github.com/vllm-project/vllm
vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure yesterday
  • No fix available
  • Severity - 8.7 (High)