plug
1.20.3
Compose web applications with functions
Current section
7 Advisories
Jump to
Current section
7 Advisories
Cookie attribute injection in Plug.Conn.Cookies.encode/2
Affected Versions
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-56814.html
- https://github.com/elixir-plug/plug/commit/0ee8afcc61466dc5f7a8f048d0632c899165b81f
- https://github.com/elixir-plug/plug/commit/56edca2ce35fe5589cd581644d8a4493fa5f484e
- https://github.com/elixir-plug/plug/commit/981597d3a4271ede64373c7a731702a42c500dd6
- https://github.com/elixir-plug/plug/commit/cae36053350e5215a4e0ca33cd130af9c5fc6364
- https://github.com/elixir-plug/plug/commit/df97d3f17f808a9916a7700a701fb85314559d56
- https://github.com/elixir-plug/plug/commit/f7effaed811c00b5f5bf817936bfd9c5df27b7dc
- https://github.com/elixir-plug/plug/security/advisories/GHSA-95qv-c9g9-rm63
- https://hex.pm/packages/plug
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-54892.html
- https://github.com/elixir-plug/plug/commit/9c5d37c440eaae92869eed7c014c47266744fadb
- https://github.com/elixir-plug/plug/commit/a61124aa625d819a218fb07f90afbac8aa85eb0e
- https://github.com/elixir-plug/plug/commit/c317d08fdcf96e17931f7419275b2b8c4bf3e951
- https://github.com/elixir-plug/plug/commit/d4e5568392a4b29e545b91e12e87d6098f976145
- https://github.com/elixir-plug/plug/commit/d737eb236f17e31a36290e39f9ef3cd86a1343bd
- https://github.com/elixir-plug/plug/security/advisories/GHSA-j43x-5hjq-rgxf
- https://hex.pm/packages/plug
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-8466.html
- https://cna.erlef.org/cves/CVE-2026-8468.html
- https://github.com/elixir-plug/plug
- https://github.com/elixir-plug/plug/commit/2cb7958d33030aa826b0c7404375844d4593d43a
- https://github.com/elixir-plug/plug/commit/33858427c7f2737d560a2e40a0c9a9270d77d1d7
- https://github.com/elixir-plug/plug/commit/aa69c5ece99c40ded88b8c6581ecc86664b0b734
- https://github.com/elixir-plug/plug/commit/d5dfffe25e975585227b1b85d247b0d14164bc45
- https://github.com/elixir-plug/plug/commit/df812a1527bae9e941965e897308a2b8bbf83a94
- https://github.com/elixir-plug/plug/security/advisories/GHSA-468c-vq7p-gh64
- https://hex.pm/packages/plug
- https://nvd.nist.gov/vuln/detail/CVE-2026-8468
- https://osv.dev/vulnerability/EEF-CVE-2026-8468
Header Injection
Affected Versions
Arbitrary Code Execution in Cookie Serialization
Affected Versions
Null Byte Injection in Plug.Static
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
206 321
yesterday
71 662
last 7 days
417 268
all time
161 159 344