Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 93 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 418 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in… | |
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the… | |
| Aplazada | Alta (8.2) | 0.42% | — | Elixir-mint MintAI | 28/9/2026 | 29/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 19/9/2026 | 22/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Elixir ProtobufAI | 17/9/2026 | 24/9/2026 | Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex,… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an arbitrary-precision accumulator with acc… | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex, decode_status_line/4 stores the… | |
| Aplazada | Media (5.9) | 0.18% | — | Ematia ElixirAI | 28/8/2026 | 1/9/2026 | Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist branch in lib/elixir/lib/inspect.ex classifies a list as a charlist using… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAIMind ElixirAIElectronAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a… | |
| Analizada | Media (5.9) | 0.40% | — | Elixir-ecto Postgrex | 7/8/2026 | 17/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir MintAI | 16/7/2026 | 16/7/2026 | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.… | |
| Aplazada | Media (6.3) | 0.50% | — | Elixir-mint MintAI | 14/7/2026 | 15/7/2026 | Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP2.handle_continuation/3 function in lib/mint/http2.ex accumulates the header-block fragment carried by each HTTP/2 CONTINUATION frame… | |
| Aplazada | Alta (8.2) | 0.50% | — | Elixir MintAI | 14/7/2026 | 15/7/2026 | Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers/4 functions in lib/mint/http1.ex accumulate every parsed response header and… | |
| Aplazada | Baja (2.1) | 0.22% | — | Elixir-ecto PostgrexAI | 10/7/2026 | 10/7/2026 | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject SQL into the reconnect replay query, causing a denial of service of the notification connection. Postgrex.Notifications sanitizes channel names with quote_channel/1, which doubles double quotes so… | |
| Aplazada | Baja (2.1) | 0.22% | — | Elixir-plug PlugAI | 10/7/2026 | 24/9/2026 | Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response header by interpolating the cookie value and its path, domain,… | |
| Aplazada | Media (6.9) | 1.1% | — | Elixir PlugAI | 10/7/2026 | 24/9/2026 | Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. The parser charges the :length limit only for part body bytes; part… | |
| Aplazada | Alta (8.7) | 0.55% | — | Elixir-mint HpaxAI | 6/7/2026 | 6/7/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding. hpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3… | |
| Aplazada | Alta (8.7) | 0.52% | — | Elixir-mint MintAI | 6/7/2026 | 6/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversized chunked transfer-encoded response. This vulnerability is associated with program files lib/mint/http1.ex and program routines 'Elixir.Mint.HTTP1':decode_body/5,… | |
| Aplazada | Alta (8.7) | 0.95% | — | Elixir PlugAI | 23/6/2026 | 23/6/2026 | Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn.Query.decode_each/2) parse query strings and application/x-www-form-urlencoded request bodies. When a key contains many bracketed segments… | |
| Aplazada | Media (5.1) | 0.22% | — | Ematia ElixirAI | 9/6/2026 | 23/7/2026 | Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to cause a denial of service through CPU and memory exhaustion. The version parser converts numeric version components (major, minor, patch and numeric pre-release/build… | |
| Modificada | Baja (2.1) | 0.34% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disposition parameter as #{k}="#{v}" with no validation of CR (\r), LF (\n), or… | |
| Modificada | Alta (8.2) | 0.63% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list… | |
| Modificada | Baja (2.1) | 0.35% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart content_type_params list… | |
| Modificada | Alta (8.2) | 0.67% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin redirects using a case-sensitive string comparison against a lowercase filter list… | |
| Modificada | Alta (8.2) | 0.70% | — | Elixir-tesla Tesla | 2/6/2026 | 24/9/2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are… |