Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vj8p-hp9x-gh47
  • Hex/mpp
mpp vulnerable to Gas Draining with low gas limit 14 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-qpxh-ff8m-c62v
  • Hex/mpp
mpp vulnerable to Gas Draining with access list 14 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-vv77-66rf-pm86
  • Hex/mpp
mpp vulnerable to Gas Draining with no limit 14 hours ago
  • Fix available
  • Severity - 8.8 (High)
EEF-CVE-2026-92106
  • Hex/lazy_html
  • github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS yesterday
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-93477
  • Hex/ash
  • github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash yesterday
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-f4hc-ppw9-4hhw
  • Hex/ash
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets yesterday
  • Fix available
  • Severity - 5.9 (Medium)
EEF-CVE-2026-91187
  • Hex/nimble_zta
  • github.com/dashbitco/nimble_zta
Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy yesterday
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-j43x-5hjq-rgxf
  • Hex/plug
Plug: quadratic-time decoding of nested query/body parameters enables denial of service 2 days ago
  • Fix available
  • Severity - 8.7 (High)
EEF-CVE-2026-87119
  • Hex/mpp
  • github.com/zenhive/mpp
mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed 4 days ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-89420
  • Hex/mpp
  • github.com/zenhive/mpp
Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free 4 days ago
  • Fix available
  • Severity - 7.1 (High)
EEF-CVE-2026-82672
  • Hex/mint
  • github.com/elixir-mint/mint
Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections 6 days ago
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-86688
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Session id is not renewed on authentication in ash_authentication, allowing session fixation 17 Sep
  • Fix available
  • Severity - 7.4 (High)
EEF-CVE-2026-76949
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-91039
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-88952
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)
EEF-CVE-2026-85500
  • Hex/ash_authentication
  • github.com/team-alembic/ash_authentication
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication 17 Sep
  • Fix available
  • Severity - 9.1 (Critical)