plug
1.19.2
Compose web applications with functions
Current section
4 Advisories
Jump to
Current section
4 Advisories
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-8466.html
- https://cna.erlef.org/cves/CVE-2026-8468.html
- https://github.com/elixir-plug/plug
- https://github.com/elixir-plug/plug/commit/2cb7958d33030aa826b0c7404375844d4593d43a
- https://github.com/elixir-plug/plug/commit/33858427c7f2737d560a2e40a0c9a9270d77d1d7
- https://github.com/elixir-plug/plug/commit/aa69c5ece99c40ded88b8c6581ecc86664b0b734
- https://github.com/elixir-plug/plug/commit/d5dfffe25e975585227b1b85d247b0d14164bc45
- https://github.com/elixir-plug/plug/commit/df812a1527bae9e941965e897308a2b8bbf83a94
- https://github.com/elixir-plug/plug/security/advisories/GHSA-468c-vq7p-gh64
- https://hex.pm/packages/plug
- https://nvd.nist.gov/vuln/detail/CVE-2026-8468
- https://osv.dev/vulnerability/EEF-CVE-2026-8468
Header Injection
Affected Versions
Arbitrary Code Execution in Cookie Serialization
Affected Versions
Null Byte Injection in Plug.Static
Affected Versions
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
420 594
yesterday
48 564
last 7 days
325 252
all time
158 896 922