Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2211854
AlmaLinux
5946
Alpaquita
16105
Alpine
4618
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030980
CleanStart
3946
CRAN
14
crates.io
2739
Debian
68614
Echo
7478
GHC
3
GIT
108488
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6232
Maven
7044
MinimOS
145135
npm
228993
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4014
Packagist
7098
Pub
11
PyPI
25205
Red Hat
23413
Rocky Linux
4317
Root
19603
RubyGems
5326
SUSE
23361
SwiftURL
60
TuxCare
9657
Ubuntu
65629
VSCode
21
Wolfi
289834
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-94194
Hex/mint
github.com/elixir-mint/mint
Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding, enabling response smuggling through intermediaries
2 days ago
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-92103
Hex/mint
github.com/elixir-mint/mint
Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size
2 days ago
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-91043
Hex/mint
github.com/elixir-mint/mint
HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exhaust client memory
2 days ago
Fix available
Severity - 8.2 (High)
GHSA-vj8p-hp9x-gh47
Hex/mpp
mpp vulnerable to Gas Draining with low gas limit
4 days ago
Fix available
Severity - 8.8 (High)
GHSA-qpxh-ff8m-c62v
Hex/mpp
mpp vulnerable to Gas Draining with access list
4 days ago
Fix available
Severity - 6.9 (Medium)
GHSA-vv77-66rf-pm86
Hex/mpp
mpp vulnerable to Gas Draining with no limit
4 days ago
Fix available
Severity - 8.8 (High)
EEF-CVE-2026-92106
Hex/lazy_html
github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
5 days ago
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-93477
Hex/ash
github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash
5 days ago
Fix available
Severity - 5.9 (Medium)
GHSA-f4hc-ppw9-4hhw
Hex/ash
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
5 days ago
Fix available
Severity - 5.9 (Medium)
EEF-CVE-2026-91187
Hex/nimble_zta
github.com/dashbitco/nimble_zta
Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy
6 days ago
Fix available
Severity - 9.3 (Critical)
GHSA-j43x-5hjq-rgxf
Hex/plug
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
23 Sep
Fix available
Severity - 8.7 (High)
EEF-CVE-2026-87119
Hex/mpp
github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed
22 Sep
Fix available
Severity - 8.2 (High)
EEF-CVE-2026-89420
Hex/mpp
github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free
22 Sep
Fix available
Severity - 7.1 (High)
EEF-CVE-2026-82672
Hex/mint
github.com/elixir-mint/mint
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections
19 Sep
Fix available
Severity - 6.3 (Medium)
EEF-CVE-2026-86688
Hex/ash_authentication
github.com/team-alembic/ash_authentication
Session id is not renewed on authentication in ash_authentication, allowing session fixation
17 Sep
Fix available
Severity - 7.4 (High)
EEF-CVE-2026-76949
Hex/ash_authentication
github.com/team-alembic/ash_authentication
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement
17 Sep
Fix available
Severity - 9.1 (Critical)
Load more...
Hex - OSV