Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-64941
  • Hex/phoenix_live_view
  • github.com/phoenixframework/phoenix_live_view
Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR yesterday
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-70395
  • Hex/ash
  • github.com/ash-project/ash
Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash yesterday
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-69659
  • Hex/ash
  • github.com/ash-project/ash
Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset yesterday
  • Fix available
  • Severity - 5.9 (Medium)
EEF-CVE-2026-67585
  • Hex/absinthe_federation
  • github.com/divvypayhq/absinthe_federation
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation 4 days ago
  • Fix available
  • Severity - 8.7 (High)
EEF-CVE-2026-66838
  • Hex/postgrex
  • github.com/elixir-ecto/postgrex
SQL injection via the :comment option in Postgrex.stream/4 4 days ago
  • Fix available
  • Severity - 5.9 (Medium)
EEF-CVE-2026-68750
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service 5 days ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-68749
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service 5 days ago
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-68747
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input 5 days ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66829
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection 5 days ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66370
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking 5 days ago
  • Fix available
  • Severity - 4.8 (Medium)
EEF-CVE-2026-66843
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding 5 days ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66885
  • Hex/livebook
  • github.com/livebook-dev/livebook
Livebook Teams identity callback lacks state binding, allowing login CSRF 5 days ago
  • Fix available
  • Severity - 6.8 (Medium)
EEF-CVE-2026-66298
  • Hex/livebook
  • github.com/livebook-dev/livebook
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts 5 days ago
  • Fix available
  • Severity - 8.6 (High)
EEF-CVE-2026-66297
  • Hex/livebook
  • github.com/livebook-dev/livebook
Unescaped deployment environment variables in generated setup commands 5 days ago
  • Fix available
  • Severity - 5.0 (Medium)
EEF-CVE-2026-66881
  • Hex/livebook
  • github.com/livebook-dev/livebook
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download 5 days ago
  • Fix available
  • Severity - 7.0 (High)
EEF-CVE-2026-68746
  • Hex/livebook
  • github.com/livebook-dev/livebook
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access 5 days ago
  • Fix available
  • Severity - 7.7 (High)