Browse all 5 CVE security advisories affecting elixir-plug. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-56813 | Cookie attribute injection in Plug.Conn.Cookies.encode/2 — plugCWE-141 | - | - | 2026-07-10 |
| CVE-2026-56814 | Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) — plugCWE-770 | - | - | 2026-07-10 |
| CVE-2026-54892 | Plug: quadratic-time decoding of nested query/body parameters enables denial of service — plugCWE-407 | - | - | 2026-06-23 |
| CVE-2026-8468 | Unbounded buffer accumulation in multipart header parsing causes denial of service in plug — plugCWE-770 | - | - | 2026-05-14 |
This page lists every published CVE security advisory associated with elixir-plug. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.