Current section

7 Advisories

Jump to
EEF-CVE-2026-56813 CVE-2026-56813 GHSA-wpmj-jh88-rpgm

Cookie attribute injection in Plug.Conn.Cookies.encode/2

July 10, 2026
CVSS
?
2.1 / 10.0 Low
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Affected Versions

>= 0.1.0 and < 1.16.6 >= 1.20.0 and < 1.20.3 >= 1.19.0 and < 1.19.5 >= 1.18.0 and < 1.18.5 >= 1.17.0 and < 1.17.4
GHSA-9h73-w7ch-rh73 CVE-2018-1000883

Header Injection

April 12, 2022
CVSS
?
6.5 / 10.0 Medium
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Versions

< 1.0.6 >= 1.1.0 and < 1.1.9 >= 1.2.0 and < 1.2.5 >= 1.3.0 and < 1.3.5
GHSA-5v4m-c73v-c7gq CVE-2017-1000053

Arbitrary Code Execution in Cookie Serialization

April 12, 2022
CVSS
?
8.1 / 10.0 High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Versions

>= 1.3.0 and < 1.3.2 >= 1.2.0 and < 1.2.3 >= 1.1.0 and < 1.1.7 < 1.0.4
GHSA-2q6v-32mr-8p8x CVE-2017-1000052

Null Byte Injection in Plug.Static

April 12, 2022
CVSS
?
7.8 / 10.0 High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Versions

>= 1.3.0 and < 1.3.2 < 1.0.4 >= 1.1.0 and < 1.1.7 >= 1.2.0 and < 1.2.3

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 20K 40K 60K 80K

this version

206 321

yesterday

71 662

last 7 days

417 268

all time

161 159 344

Last Updated

Jul 09, 2026

License

Apache-2.0

Build Tools

mix

Publisher

josevalim josevalim

Links