plug
1.20.1
Compose web applications with functions
Current section
5 Advisories
Jump to
Current section
5 Advisories
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-54892.html
- https://github.com/elixir-plug/plug/commit/9c5d37c440eaae92869eed7c014c47266744fadb
- https://github.com/elixir-plug/plug/commit/a61124aa625d819a218fb07f90afbac8aa85eb0e
- https://github.com/elixir-plug/plug/commit/c317d08fdcf96e17931f7419275b2b8c4bf3e951
- https://github.com/elixir-plug/plug/commit/d4e5568392a4b29e545b91e12e87d6098f976145
- https://github.com/elixir-plug/plug/commit/d737eb236f17e31a36290e39f9ef3cd86a1343bd
- https://github.com/elixir-plug/plug/security/advisories/GHSA-j43x-5hjq-rgxf
- https://hex.pm/packages/plug
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-8466.html
- https://cna.erlef.org/cves/CVE-2026-8468.html
- https://github.com/elixir-plug/plug
- https://github.com/elixir-plug/plug/commit/2cb7958d33030aa826b0c7404375844d4593d43a
- https://github.com/elixir-plug/plug/commit/33858427c7f2737d560a2e40a0c9a9270d77d1d7
- https://github.com/elixir-plug/plug/commit/aa69c5ece99c40ded88b8c6581ecc86664b0b734
- https://github.com/elixir-plug/plug/commit/d5dfffe25e975585227b1b85d247b0d14164bc45
- https://github.com/elixir-plug/plug/commit/df812a1527bae9e941965e897308a2b8bbf83a94
- https://github.com/elixir-plug/plug/security/advisories/GHSA-468c-vq7p-gh64
- https://hex.pm/packages/plug
- https://nvd.nist.gov/vuln/detail/CVE-2026-8468
- https://osv.dev/vulnerability/EEF-CVE-2026-8468
Header Injection
Affected Versions
Arbitrary Code Execution in Cookie Serialization
Affected Versions
Null Byte Injection in Plug.Static
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
36 027
yesterday
51 051
last 7 days
342 104
all time
159 899 286