Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13 advisories

Loading
Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder High
CVE-2026-39806 was published for bandit (Erlang) May 19, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked` High
CVE-2026-39803 was published for bandit (Erlang) May 19, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3` High
CVE-2026-32687 was published for postgrex (Erlang) May 18, 2026
PJUllrich Credited to PJUllrich
Absinthe: Quadratic fragment-name uniqueness check High
CVE-2026-43967 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
Absinthe: Unbounded atom creation from parsed directive name High
CVE-2026-42793 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
Decimal: Unbounded exponent in `Decimal.new` enables unauthenticated DoS Moderate
CVE-2026-32686 was published for decimal (Erlang) May 12, 2026
PJUllrich Credited to PJUllrich, ericmj, josevalim, wojtekmach, maennchen, ruslandoga, and warmwaffles ericmj ericmj
josevalim josevalim wojtekmach wojtekmach maennchen maennchen ruslandoga ruslandoga warmwaffles warmwaffles
Phoenix: Long-poll NDJSON body splitting causes large memory allocation High
CVE-2026-32689 was published for phoenix (Erlang) May 8, 2026
PJUllrich Credited to PJUllrich
Bandit HTTP/2 Frame Size Limit Bypass via Late Buffer Check Enables Memory Exhaustion Moderate
CVE-2026-42788 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
Bandit trusts client-supplied URI scheme on plaintext connections Moderate
CVE-2026-39807 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit is vulnerable to CL.CL request smuggling via unrejected duplicate `Content-Length` header Moderate
CVE-2026-39805 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame High
CVE-2026-39804 was published for bandit (Erlang) May 7, 2026
PJUllrich Credited to PJUllrich, mtrudel, and maennchen mtrudel mtrudel
maennchen maennchen
Plug.Cowboy vulnerable to unauthenticated remote DoS via HTTP/2 `:scheme` atom-table exhaustion High
CVE-2026-32688 was published for plug_cowboy (Erlang) May 5, 2026
PJUllrich Credited to PJUllrich
ProTip! Advisories are also available from the GraphQL API