VulnSea

Tagged “erlang”

CVEs tagged erlang, newest first.

42 CVEsRSS

CVE-2026-47069Low
2mo ago

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

Sunlithackney · hackneyEPSS 0.43%via GHSA
CVE-2026-47070Medium
2mo ago

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

Sunlithackney · hackneyEPSS 0.37%via GHSA
CVE-2026-47074High
2mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Twilighthackney · hackneyEPSS 0.23%via GHSA
CVE-2026-47075Medium
2mo ago

Hackney has CR/LF injection in query parameter

Hackney has CR/LF injection in query parameter

Sunlithackney · hackneyEPSS 0.48%via GHSA
CVE-2026-47072Medium
2mo ago

Hackney has CRLF / header injection in WebSocket upgrade request

Hackney has CRLF / header injection in WebSocket upgrade request

Sunlithackney · hackneyEPSS 0.54%via GHSA
CVE-2026-47073High
2mo ago

Hackney has unbounded buffer accumulation in WebSocket

Hackney has unbounded buffer accumulation in WebSocket

Twilighthackney · hackneyEPSS 0.85%via GHSA
CVE-2026-47067High
2mo ago

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

Twilighthackney · hackneyEPSS 0.75%via GHSA
GHSA-8jgf-23q5-x7xxHigh
2mo ago

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

Twilightex_aws_sns · ex_aws_snsvia GHSA
CVE-2026-48591Medium
3mo ago

earmark: Stored XSS via unescaped HTML attribute values

earmark: Stored XSS via unescaped HTML attribute values

Sunlitearmark · earmarkEPSS 0.13%via GHSA
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-8469High
3mo ago

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

Twilightphoenix_storybook · phoenix_storybookEPSS 0.54%via GHSA
CVE-2026-47068Low
3mo ago

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

Sunlitphoenix_storybook · phoenix_storybookEPSS 0.45%via GHSA
CVEs tagged “erlang” — page 2 · VulnSea