Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
417638
AlmaLinux
3997
Alpaquita
6765
Alpine
3859
Android
3013
BellSoft Hardened Containers
218
Bitnami
6051
Chainguard
31166
CRAN
11
crates.io
1800
Debian
49443
Echo
1812
GHC
3
GIT
63711
GitHub Actions
37
Go
4701
Hackage
24
Hex
38
Linux
13573
Mageia
5669
Maven
5917
MinimOS
3887
npm
69125
NuGet
1468
openEuler
5091
openSUSE
10188
OSS-Fuzz
3686
Packagist
4820
Pub
10
PyPI
16652
Red Hat
17132
Rocky Linux
2250
RubyGems
1790
SUSE
16771
SwiftURL
42
Ubuntu
47026
Wolfi
15892
ID
Packages
Summary
Published
arrow_upward
Attributes
HSEC-2025-0005
Hackage/cabal-install
cabal-install dependency confusion
13 Jul
Fix available
HSEC-2025-0004
Hackage/spacecookie
Broken Path Sanitization in spacecookie Library
06 May
Fix available
HSEC-2025-0003
Hackage/xz-clib
Use after free in multithreaded lzma (.xz) decoder
03 Apr
Fix available
HSEC-2025-0002
Hackage/cryptonite
Hackage/crypton
Double Public Key Signing Function Oracle Attack on Ed25519
03 Apr
Fix available
HSEC-2024-0006
Hackage/base
fromIntegral: conversion error
20 Mar
Fix available
HSEC-2024-0009
Hackage/biscuit-haskell
Public key confusion in third-party blocks
01 Aug 2024
Fix available
HSEC-2024-0003
Hackage/process
process: command injection via argument list on Windows
09 Apr 2024
Fix available
HSEC-2024-0002
Hackage/bzlib
Hackage/bz2
Hackage/bzlib-conduit
out-of-bounds write when there are many bzip2 selectors
11 Mar 2024
Fix available
HSEC-2024-0001
Hackage/keter
Reflected XSS vulnerability in keter
27 Feb 2024
Fix available
HSEC-2023-0015
Hackage/cabal-install
cabal-install uses expired key policies
07 Nov 2023
Fix available
HSEC-2023-0014
Hackage/pandoc
Arbitrary file write is possible when using PDF output or --extract-media with untrusted input
22 Aug 2023
Fix available
HSEC-2023-0009
Hackage/git-annex
git-annex command injection via malicious SSH hostname
25 Jul 2023
Fix available
HSEC-2023-0010
Hackage/git-annex
git-annex private data exfiltration to compromised remote
25 Jul 2023
Fix available
HSEC-2023-0011
Hackage/git-annex
git-annex GPG decryption attack via compromised remote
25 Jul 2023
Fix available
HSEC-2023-0012
Hackage/git-annex
git-annex checksum exposure to encrypted special remotes
25 Jul 2023
Fix available
HSEC-2023-0013
Hackage/git-annex
git-annex plaintext storage of embedded credentials on encrypted remotes
25 Jul 2023
Fix available
Load more...
(1 page left)
Hackage - OSV