Advisories list

The Haskell Security Advisory Database is a repository of security advisories filed against packages published via Hackage.

It is generated from Haskell Security Advisory Database. Feel free to report new or historic security issues.

#Package(s)Summary
HSEC-2025-0006@hackage/x509-store,@hackage/crypton-x509-storePrivate key leak via inherited file descriptor
HSEC-2025-0005@hackage/cabal-installcabal-install dependency confusion
HSEC-2025-0004@hackage/spacecookieBroken Path Sanitization in spacecookie Library
HSEC-2025-0003@hackage/xz-clibUse after free in multithreaded lzma (.xz) decoder
HSEC-2025-0002@hackage/cryptonite,@hackage/cryptonDouble Public Key Signing Function Oracle Attack on Ed25519
HSEC-2025-0001ghc:ghcSubword division operations may produce incorrect results
HSEC-2024-0009@hackage/biscuit-haskellPublic key confusion in third-party blocks
HSEC-2024-0008ghc:ghc,ghc:ghc,ghc:ghcSign extension error in the PPC64le FFI
HSEC-2024-0007ghc:ghc,ghc:ghcSign extension error in the AArch64 NCG
HSEC-2024-0006@hackage/basefromIntegral: conversion error
HSEC-2024-0003@hackage/processprocess: command injection via argument list on Windows
HSEC-2024-0002@hackage/bzlib,@hackage/bz2,@hackage/bzlib-conduitout-of-bounds write when there are many bzip2 selectors
HSEC-2024-0001@hackage/keterReflected XSS vulnerability in keter
HSEC-2023-0015@hackage/cabal-installcabal-install uses expired key policies
HSEC-2023-0014@hackage/pandocArbitrary file write is possible when using PDF output or --extract-media with untrusted input
HSEC-2023-0013@hackage/git-annexgit-annex plaintext storage of embedded credentials on encrypted remotes
HSEC-2023-0012@hackage/git-annexgit-annex checksum exposure to encrypted special remotes
HSEC-2023-0011@hackage/git-annexgit-annex GPG decryption attack via compromised remote
HSEC-2023-0010@hackage/git-annexgit-annex private data exfiltration to compromised remote
HSEC-2023-0009@hackage/git-annexgit-annex command injection via malicious SSH hostname
HSEC-2023-0008@hackage/hledger-webStored XSS in hledger-web
HSEC-2023-0007@hackage/base,@hackage/toml-readerreadFloat: memory exhaustion with large exponent
HSEC-2023-0006@hackage/x509-validationx509-validation does not enforce pathLenConstraint
HSEC-2023-0005@hackage/tls-extratls-extra: certificate validation does not check Basic Constraints
HSEC-2023-0004@hackage/xml-conduitxml-conduit unbounded entity expansion
HSEC-2023-0003@hackage/xmonad-contribcode injection in xmonad-contrib
HSEC-2023-0002@hackage/biscuit-haskellImproper Verification of Cryptographic Signature
HSEC-2023-0001@hackage/aesonHash flooding vulnerability in aeson