Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
378887
AlmaLinux
3900
Alpaquita
5741
Alpine
3783
Android
2911
BellSoft Hardened Containers
187
Bitnami
5896
Chainguard
28705
CRAN
11
crates.io
1747
Debian
47416
GHC
3
GIT
48783
GitHub Actions
32
Go
4541
Hackage
24
Hex
37
Linux
13573
Mageia
5655
Maven
5783
MinimOS
3100
npm
62520
NuGet
1449
openSUSE
10140
OSS-Fuzz
3654
Packagist
4776
Pub
10
PyPI
16272
Red Hat
16752
Rocky Linux
1927
RubyGems
1707
SUSE
16628
SwiftURL
36
Ubuntu
45500
Wolfi
15688
ID
Packages
Summary
Published
arrow_upward
Attributes
HSEC-2025-0005
Hackage/cabal-install
cabal-install dependency confusion
13 Jul
Fix available
HSEC-2025-0004
Hackage/spacecookie
Broken Path Sanitization in spacecookie Library
06 May
Fix available
HSEC-2025-0003
Hackage/xz-clib
Use after free in multithreaded lzma (.xz) decoder
03 Apr
Fix available
HSEC-2025-0002
Hackage/cryptonite
Hackage/crypton
Double Public Key Signing Function Oracle Attack on Ed25519
03 Apr
Fix available
HSEC-2024-0006
Hackage/base
fromIntegral: conversion error
20 Mar
Fix available
HSEC-2024-0009
Hackage/biscuit-haskell
Public key confusion in third-party blocks
01 Aug 2024
Fix available
HSEC-2024-0003
Hackage/process
process: command injection via argument list on Windows
09 Apr 2024
Fix available
HSEC-2024-0002
Hackage/bzlib
Hackage/bz2
Hackage/bzlib-conduit
out-of-bounds write when there are many bzip2 selectors
11 Mar 2024
Fix available
HSEC-2024-0001
Hackage/keter
Reflected XSS vulnerability in keter
27 Feb 2024
Fix available
HSEC-2023-0015
Hackage/cabal-install
cabal-install uses expired key policies
07 Nov 2023
Fix available
HSEC-2023-0014
Hackage/pandoc
Arbitrary file write is possible when using PDF output or --extract-media with untrusted input
22 Aug 2023
Fix available
HSEC-2023-0009
Hackage/git-annex
git-annex command injection via malicious SSH hostname
25 Jul 2023
Fix available
HSEC-2023-0010
Hackage/git-annex
git-annex private data exfiltration to compromised remote
25 Jul 2023
Fix available
HSEC-2023-0011
Hackage/git-annex
git-annex GPG decryption attack via compromised remote
25 Jul 2023
Fix available
HSEC-2023-0012
Hackage/git-annex
git-annex checksum exposure to encrypted special remotes
25 Jul 2023
Fix available
HSEC-2023-0013
Hackage/git-annex
git-annex plaintext storage of embedded credentials on encrypted remotes
25 Jul 2023
Fix available
Load more...
(1 page left)
Hackage - OSV