|
1981
|
- |
|
-
|
-
|
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command.
This issue was fixed…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-35087
|
2026-05-27 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1982
|
4.3 |
MEDIUM
Network
|
traccar
|
traccar
|
Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44314
|
2026-05-27 23:02 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1983
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiat…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47071
|
2026-05-27 22:56 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1984
|
6.1 |
MEDIUM
Network
|
benoitc
|
hackney
|
Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect handler in src/hackney_h3.erl passes the original request headers unchanged to th…
|
CWE-601
Open Redirect
|
CVE-2026-47070
|
2026-05-27 22:55 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1985
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee fo…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-47066
|
2026-05-27 22:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1986
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47073
|
2026-05-27 22:54 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1987
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47077
|
2026-05-27 22:53 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1988
|
5.3 |
MEDIUM
Network
|
benoitc
|
hackney
|
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Splitting. The hackney_cookie:setcookie/3 function in src/hackney_cookie.erl validat…
|
CWE-93
CRLF Injection
|
CVE-2026-47069
|
2026-05-27 22:53 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1989
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-47067
|
2026-05-27 22:52 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1990
|
6.5 |
MEDIUM
Local
|
benoitc
|
hackney
|
Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{}…
|
CWE-436 CWE-918
Interpretation Conflict Server-Side Request Forgery (SSRF)
|
CVE-2026-47076
|
2026-05-27 22:51 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|