Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

32 advisories

Loading
Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service High
CVE-2026-8468 was published for plug (Erlang) May 20, 2026
maennchen Credited to maennchen and josevalim josevalim josevalim
Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder High
CVE-2026-39806 was published for bandit (Erlang) May 19, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked` High
CVE-2026-39803 was published for bandit (Erlang) May 19, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3` High
CVE-2026-32687 was published for postgrex (Erlang) May 18, 2026
PJUllrich Credited to PJUllrich
Absinthe: Quadratic fragment-name uniqueness check High
CVE-2026-43967 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
Absinthe: Unbounded atom creation from parsed directive name High
CVE-2026-42793 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
cowlib: Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame High
CVE-2026-43970 was published for cowlib (Erlang) May 13, 2026
Phoenix: Long-poll NDJSON body splitting causes large memory allocation High
CVE-2026-32689 was published for phoenix (Erlang) May 8, 2026
PJUllrich Credited to PJUllrich
ex_webrtc client-role handshake is missing DTLS peer fingerprint validation High
CVE-2026-44700 was published for ex_webrtc (Erlang) May 8, 2026
songxpu Credited to songxpu
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame High
CVE-2026-39804 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion High
CVE-2026-32688 was published for plug_cowboy (Erlang) May 5, 2026
PJUllrich Credited to PJUllrich
wisp has Allocation of Resources Without Limits or Throttling High
CVE-2026-32145 was published for wisp (Erlang) Apr 3, 2026
jtdowney Credited to jtdowney and lpil lpil lpil
fg0x0 Credited to fg0x0 and zachdaniel zachdaniel zachdaniel
AmanTallarium Credited to AmanTallarium, nemophrost, s3cur3, and dweill nemophrost nemophrost
s3cur3 s3cur3 dweill dweill
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe High
CVE-2026-32873 was published for ewe (Erlang) Mar 16, 2026
jtdowney Credited to jtdowney
Wisp Vulnerable to Path Traversal High
CVE-2026-28807 was published for wisp (Erlang) Mar 11, 2026
jtdowney Credited to jtdowney and lpil lpil lpil
Ash has authorization bypass when bypass policy condition evaluates to true High
CVE-2025-48044 was published for ash (Erlang) Oct 17, 2025
jechol Credited to jechol, maennchen, and zachdaniel maennchen maennchen
zachdaniel zachdaniel
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies High
CVE-2025-48043 was published for ash (Erlang) Oct 13, 2025
maennchen Credited to maennchen and zachdaniel zachdaniel zachdaniel
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden High
CVE-2025-48042 was published for ash (Erlang) Sep 15, 2025
zachdaniel Credited to zachdaniel and maennchen maennchen maennchen
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission High
CVE-2024-51988 was published for rabbit_common (Erlang) Nov 6, 2024
bedla Credited to bedla, anhanhnguyen, and michaelklishin anhanhnguyen anhanhnguyen
michaelklishin michaelklishin
MTProto proxy remote code execution vulnerability High
CVE-2023-45312 was published for mtproto_proxy (Erlang) Oct 10, 2023
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows High
CVE-2023-35174 was published for livebook (Erlang) Jun 21, 2023
maple3142 Credited to maple3142
ProTip! Advisories are also available from the GraphQL API