Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-92106
  • Hex/lazy_html
  • github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS 11 hours ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-93477
  • Hex/ash
  • github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash 14 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-f4hc-ppw9-4hhw
  • Hex/ash
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets yesterday
  • Fix available
  • Severity - 5.9 (Medium)
EEF-CVE-2026-91187
  • Hex/nimble_zta
  • github.com/dashbitco/nimble_zta
Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy yesterday
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-j43x-5hjq-rgxf
  • Hex/plug
Plug: quadratic-time decoding of nested query/body parameters enables denial of service 2 days ago
  • Fix available
  • Severity - 8.7 (High)
EEF-CVE-2026-87119
  • Hex/mpp
  • github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed 3 days ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-89420
  • Hex/mpp
  • github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free 3 days ago
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-82672
  • Hex/mint
  • github.com/elixir-mint/mint
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections 6 days ago
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-86688
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Session id is not renewed on authentication in ash_authentication, allowing session fixation 17 Sep
  • Fix available
  • Severity - 7.4 (High)
EEF-CVE-2026-76949
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-91039
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-88952
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-85500
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-86533
  • Hex/ash_authentication
  • Hex/ash_authentication_phoenix
  • github.com/team-alembic/ash_authentication
  • github.com/team-alembic/ash_authentication_phoenix
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-81632
  • Hex/ash_authentication
  • Hex/ash_authentication_phoenix
  • github.com/team-alembic/ash_authentication
  • github.com/team-alembic/ash_authentication_phoenix
Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix 17 Sep
  • Fix available
  • Severity - 7.2 (High)
EEF-CVE-2026-80218
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Sign-in token minted for one resource accepted by another in AshAuthentication 17 Sep
  • Fix available
  • Severity - 7.6 (High)