Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
655547
AlmaLinux
4783
Alpaquita
9505
Alpine
4125
Android
3262
Azure Linux
12016
BellSoft Hardened Containers
466
Bitnami
7822
Chainguard
6233
CleanStart
815
CRAN
14
crates.io
2380
Debian
56024
Echo
3980
GHC
3
GIT
81549
GitHub Actions
50
Go
6842
Hackage
30
Hex
89
Julia
826
Linux
15361
Mageia
5916
Maven
6469
MinimOS
40771
npm
218247
NuGet
1679
opam
12
openEuler
6749
openSUSE
12771
OSS-Fuzz
3870
Packagist
6248
Pub
11
PyPI
19161
Red Hat
19855
Rocky Linux
3058
Root
14000
RubyGems
1961
SUSE
20561
SwiftURL
51
Ubuntu
54006
VSCode
18
Wolfi
3958
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9mhv-8h52-q7q2
Hex/absinthe
Absinthe: Quadratic fragment-name uniqueness check
3 days ago
Fix available
Severity - 8.7 (High)
GHSA-qf4g-9fqq-mmm7
Hex/absinthe
Absinthe: Unbounded atom creation from parsed directive name
3 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-8468
Hex/plug
github.com/elixir-plug/plug
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
3 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-43970
Hex/cowlib
github.com/ninenines/cowlib
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
3 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-8466
Hex/cowboy
github.com/ninenines/cowboy
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
3 days ago
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-39806
Hex/bandit
github.com/mtrudel/bandit
HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit
4 days ago
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-39803
Hex/bandit
github.com/mtrudel/bandit
HTTP/1 chunked body reader ignores length cap in bandit
4 days ago
Fix available
Severity - 8.7 (High)
GHSA-rhv4-8758-jx7v
Hex/decimal
Decimal: Unbounded exponent in
`
Decimal.new
`
enables unauthenticated DoS
5 days ago
Fix available
Severity - 6.9 (Medium)
EEF-CVE-2026-32687
Hex/postgrex
github.com/elixir-ecto/postgrex.git
SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3
5 days ago
Fix available
Severity - 7.5 (High)
EEF-CVE-2026-43968
Hex/cowlib
github.com/ninenines/cowlib
CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
5 days ago
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-7790
Hex/cowlib
github.com/ninenines/cowlib
Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
5 days ago
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-43969
Hex/cowlib
github.com/ninenines/cowlib
Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
5 days ago
No fix available
Severity - 2.1 (Low)
GHSA-628h-q48j-jr6q
Hex/phoenix
Phoenix: Long-poll NDJSON body splitting causes large memory allocation
08 May
Fix available
Severity - 8.7 (High)
GHSA-c62g-j346-39v5
Hex/absinthe_plug
absinthe_plug Has a Cross-site Scripting vulnerability
08 May
No fix available
Severity - 2.3 (Low)
GHSA-qwfw-ggxw-577c
Hex/ex_webrtc
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation
08 May
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-42793
Hex/absinthe
github.com/absinthe-graphql/absinthe
Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe
08 May
Fix available
Severity - 8.2 (High)
Load more...
Hex - OSV