Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-67585
  • Hex/absinthe_federation
  • github.com/divvypayhq/absinthe_federation
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation 16 hours ago
  • Fix available
  • Severity - 8.7 (High)
EEF-CVE-2026-66838
  • Hex/postgrex
  • github.com/elixir-ecto/postgrex
SQL injection via the :comment option in Postgrex.stream/4 20 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
EEF-CVE-2026-68750
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service yesterday
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-68749
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service yesterday
  • Fix available
  • Severity - 8.2 (High)
EEF-CVE-2026-68747
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input yesterday
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66829
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection yesterday
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66370
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking yesterday
  • Fix available
  • Severity - 4.8 (Medium)
EEF-CVE-2026-66843
  • Hex/html_sanitize_ex
  • github.com/rrrene/html_sanitize_ex
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding yesterday
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-66885
  • Hex/livebook
  • github.com/livebook-dev/livebook
Livebook Teams identity callback lacks state binding, allowing login CSRF 2 days ago
  • Fix available
  • Severity - 6.8 (Medium)
EEF-CVE-2026-66298
  • Hex/livebook
  • github.com/livebook-dev/livebook
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts 2 days ago
  • Fix available
  • Severity - 8.6 (High)
EEF-CVE-2026-66297
  • Hex/livebook
  • github.com/livebook-dev/livebook
Unescaped deployment environment variables in generated setup commands 2 days ago
  • Fix available
  • Severity - 5.0 (Medium)
EEF-CVE-2026-66881
  • Hex/livebook
  • github.com/livebook-dev/livebook
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download 2 days ago
  • Fix available
  • Severity - 7.0 (High)
EEF-CVE-2026-68746
  • Hex/livebook
  • github.com/livebook-dev/livebook
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access 2 days ago
  • Fix available
  • Severity - 7.7 (High)
EEF-CVE-2026-66883
  • Hex/oidcc_plug
  • github.com/erlef/oidcc_plug
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup 3 days ago
  • Fix available
  • Severity - 6.3 (Medium)
EEF-CVE-2026-66884
  • Hex/oidcc_plug
  • github.com/erlef/oidcc_plug
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection 3 days ago
  • Fix available
  • Severity - 2.1 (Low)
EEF-CVE-2026-66296
  • Hex/oaskit
  • github.com/lud/oaskit
Reflected XSS in oaskit's default HTML error handler 4 days ago
  • Fix available
  • Severity - 5.1 (Medium)