Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
695797
AlmaLinux
4993
Alpaquita
10063
Alpine
4158
Android
3401
Azure Linux
12016
BellSoft Hardened Containers
483
Bitnami
7994
Chainguard
6771
CleanStart
1266
CRAN
14
crates.io
2442
Debian
57658
Echo
5154
GHC
3
GIT
81640
GitHub Actions
52
Go
7050
Hackage
32
Hex
129
Julia
936
Linux
15361
Mageia
5949
Maven
6530
MinimOS
63077
npm
219637
NuGet
1713
opam
16
openEuler
6929
openSUSE
12935
OSS-Fuzz
3916
Packagist
6383
Pub
11
PyPI
19960
Red Hat
20394
Rocky Linux
3338
Root
15387
RubyGems
1969
SUSE
20561
SwiftURL
53
TuxCare
5651
Ubuntu
55360
VSCode
20
Wolfi
4392
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-43966
Hex/cowlib
github.com/ninenines/cowlib
HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
10 hours ago
No fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-49755
Hex/req
github.com/wojtekmach/req.git
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
11 hours ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-49756
Hex/req
github.com/wojtekmach/req.git
Multipart form-data header injection in Req via unescaped name/filename/content_type
11 hours ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-43973
Hex/gun
github.com/ninenines/gun.git
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
12 hours ago
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-43972
Hex/gun
github.com/ninenines/gun.git
gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection
12 hours ago
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-43974
Hex/gun
github.com/ninenines/gun.git
gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM
12 hours ago
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-48596
Hex/tesla
github.com/elixir-tesla/tesla.git
CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
6 days ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-48594
Hex/tesla
github.com/elixir-tesla/tesla.git
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
6 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-48595
Hex/tesla
github.com/elixir-tesla/tesla.git
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
6 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-48597
Hex/tesla
github.com/elixir-tesla/tesla.git
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
6 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-48598
Hex/tesla
github.com/elixir-tesla/tesla.git
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
6 days ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-49753
Hex/mint
github.com/elixir-mint/mint.git
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
6 days ago
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-49754
Hex/mint
github.com/elixir-mint/mint.git
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
6 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-48862
Hex/mint
github.com/elixir-mint/mint.git
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
6 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-48861
Hex/mint
github.com/elixir-mint/mint.git
CRLF injection in HTTP/1 request line via unvalidated method in Mint
6 days ago
Fix available
Severity - 2.1 (Low)
EEF-CVE-2026-47074
Hex/ex_aws_sns
github.com/ex-aws/ex_aws_sns
ex_aws_sns SigningCertURL not validated in verify_message/1
28 May
Fix available
Severity - 8.7 (High)
Load more...
Hex - OSV