plug
Hex7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting plugpage 1 of 1
- CVE-2017-1000052HIGHCVSS 7.8EG 7.8fixed in 1.0.4, 1.1.7, 1.2.3 or 1.3.2, by version range2017-07-17
vulnerable: 1.3.0, 1.3.1
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
- CVE-2017-1000053HIGHCVSS 8.1EG 8.1fixed in 1.0.4, 1.1.7, 1.2.3 or 1.3.2, by version range2017-07-17
vulnerable: 1.3.0, 1.3.1
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
- CVE-2018-1000883MEDIUMCVSS 6.5EG 6.5fixed in 1.0.6, 1.1.9, 1.2.5 or 1.3.5, by version range2018-12-20
vulnerable: 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vuln…
- CVE-2026-54892HIGHCVSS 8.7EG 8.7fixed in 1.15.5, 1.16.4, 1.17.2, 1.18.3 or 1.19.3, by version range2026-06-23
vulnerable: 1.19.0, 1.19.1, 1.19.2
Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn.Query.decode_each/2) parse query strings and application/x-…
- CVE-2026-56813LOWCVSS 2.1EG 2.1fixed in 1.16.6, 1.17.4, 1.18.5, 1.19.5 or 1.20.3, by version range2026-07-10
vulnerable: 0.10.0 ... 1.9.0 (132 versions)
Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set…
- CVE-2026-56814MEDIUMCVSS 6.9EG 6.9fixed in 1.16.6, 1.17.4, 1.18.5, 1.19.5 or 1.20.3, by version range2026-07-10
vulnerable: 1.10.0 ... 1.9.0 (73 versions)
Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of s…
- CVE-2026-8468HIGHCVSS 8.2EG 8.2fixed in 1.15.4, 1.16.3, 1.17.1, 1.18.2 or 1.19.2, by version range2026-05-14
vulnerable: 1.19.0, 1.19.1
Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex doe…
Check whether plug is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for plug CVEs against the assets you own.
Book a Demo →