Tagged “erlang”
CVEs tagged erlang, newest first.
42 CVEsRSS
CVE-2026-47069LowHackney has CRLF / header injection via unvalidated `domain` and `path` options
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
CVE-2026-47070MediumHackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
CVE-2026-47074HighHackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
CVE-2026-47075MediumHackney has CR/LF injection in query parameter
Hackney has CR/LF injection in query parameter
CVE-2026-47072MediumHackney has CRLF / header injection in WebSocket upgrade request
Hackney has CRLF / header injection in WebSocket upgrade request
CVE-2026-47073HighHackney has unbounded buffer accumulation in WebSocket
Hackney has unbounded buffer accumulation in WebSocket
CVE-2026-47067HighHackney vulnerable to atom-table exhaustion via unrecognized URL schemes
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
GHSA-8jgf-23q5-x7xxHighex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
CVE-2026-48591Mediumearmark: Stored XSS via unescaped HTML attribute values
earmark: Stored XSS via unescaped HTML attribute values
CVE-2026-8467CriticalPoCPhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
CVE-2026-8469HighPhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
CVE-2026-47068LowPhoenixStorybook has cross-session PubSub topic injection via URL parameter
PhoenixStorybook has cross-session PubSub topic injection via URL parameter