Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-66353
  • Hex/doggo
  • github.com/woylie/doggo
Doggo vulnerable to cross-site scripting via unescaped date field values 7 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-777c-2fxx-qr28
  • Hex/ash_authentication
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching 2 days ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-6ccx-9c9f-327w
  • Hex/grpc
gRPC Erlang package has unbounded gzip decompression (decompression bomb) 2 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-q8gf-9rvj-gmgj
  • Hex/grpc
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` 2 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-mwr4-5g34-j5cq
  • Hex/grpc
gRPC Erlang package's path bindings are overridable by query string and request body 2 days ago
  • Fix available
  • Severity - 7.6 (High)
GHSA-grp7-v8xh-rj7h
  • Hex/grpc
gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads 2 days ago
  • Fix available
  • Severity - 9.2 (Critical)
EEF-CVE-2026-65633
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Purpose-limited JWT accepted as full bearer authentication in AshAuthentication 2 days ago
  • Fix available
  • Severity - 7.6 (High)
EEF-CVE-2026-66882
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Reflected XSS in AshAuthentication confirmation and magic link interaction forms 2 days ago
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-47079
  • Hex/xml_builder
  • github.com/joshnuss/xml_builder
Round-trip Corruption via Improper Entity Escaping in xml_builder 6 days ago
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-48590
  • Hex/xml_builder
  • github.com/joshnuss/xml_builder
Element and Attribute Names Injected Verbatim into XML Output in xml_builder 6 days ago
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-47080
  • Hex/xml_builder
  • github.com/joshnuss/xml_builder
CDATA Section Breakout via Unsanitised ]]> in xml_builder 6 days ago
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-75484
  • Hex/bandit
  • github.com/mtrudel/bandit
HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit 20 Aug
  • Fix available
  • Severity - 6.9 (Medium)
EEF-CVE-2026-74836
  • Hex/bandit
  • github.com/mtrudel/bandit
HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit 20 Aug
  • Fix available
  • Severity - 8.7 (High)
EEF-CVE-2026-53424
  • Hex/samly
  • github.com/dropbox/samly
  • github.com/handnot2/samly
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions 20 Aug
  • No fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-53425
  • Hex/samly
  • github.com/dropbox/samly
  • github.com/handnot2/samly
Missing InResponseTo validation in Samly allows acceptance of unsolicited SAML responses 20 Aug
  • No fix available
  • Severity - 7.6 (High)
EEF-CVE-2026-67581
  • Hex/mpp
  • github.com/zenhive/mpp
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay 19 Aug
  • Fix available
  • Severity - 8.7 (High)