Known vulnerabilities in erlang-hipe

Vendor: openEuler
Software: erlang-hipe
Software CPE: cpe:2.3:o:openeuler:erlang-hipe:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 22
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting erlang-hipe erlang-hipe is affected by 22 known vulnerabilities: 1 critical, 3 high, 10 medium, 8 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136828 - Observable Response Discrepancy
CVE-2026-53422
CWE-204 Low
No
No
23.3.4.9-11 02.07.2026 SB2026070297
SB2026071924
SB2026071925
and 2 more
#VU136827 - Use of Default Cryptographic Key
CVE-2026-54887
CWE-1394 Low
No
No
23.3.4.9-11 02.07.2026 SB2026070297
SB2026071924
SB2026071925
and 2 more
#VU136826 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-54886
CWE-835 Low
No
No
23.3.4.9-11 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 4 more
#VU136825 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVE-2026-54891
CWE-924 Medium
No
No
23.3.4.9-11 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 4 more
#VU136823 - Improper Validation of Specified Quantity in Input
CVE-2026-55952
CWE-1284 Medium
No
No
23.3.4.9-11 02.07.2026 SB2026070297
SB2026071054
SB2026071055
and 4 more
#VU136821 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48855
CWE-200 Low
No
No
23.3.4.9-11 02.07.2026 SB2026070296
SB2026070301
SB2026070302
and 4 more
#VU136820 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-48856
CWE-601 Medium
No
No
23.3.4.9-11 02.07.2026 SB2026070296
SB2026071924
SB2026071925
and 2 more
#VU136818 - Server-Side Request Forgery (SSRF)
CVE-2026-48858
CWE-918 Low
No
No
23.3.4.9-11 02.07.2026 SB2026070296
SB2026071054
SB2026071055
and 4 more
#VU136817 - Stack-based buffer overflow
CVE-2026-49759
CWE-121 Medium
No
No
23.3.4.9-11 02.07.2026 SB2026070296
SB2026071054
SB2026071055
and 4 more
#VU136816 - Stack-based buffer overflow
CVE-2026-49760
CWE-121 Medium
No
No
23.3.4.9-11 02.07.2026 SB2026070296
SB2026071924
SB2026071925
and 2 more
#VU125775 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-23941
CWE-444 High
No
No
23.3.4.9-10 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125774 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23942
CWE-22 Low
No
No
23.3.4.9-10 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 6 more
#VU125773 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-23943
CWE-409 Medium
No
No
23.3.4.9-10 10.04.2026 SB2026041022
SB2026041027
SB2026041028
and 5 more
#VU125772 - Relative Path Traversal
CVE-2026-21620
CWE-23 Low
No
No
23.3.4.9-10 10.04.2026 SB2026041021
SB2026041023
SB2026041024
and 6 more
#VU117393 - Resource exhaustion
CVE-2025-48041
CWE-400 Medium
No
No
23.3.4.9-8 20.10.2025 SB2025102052
SB2025102180
SB2025102745
and 3 more
#VU117391 - Resource exhaustion
CVE-2025-48039
CWE-400 Medium
No
No
23.3.4.9-8 20.10.2025 SB2025102052
SB2025102180
SB20260105126
and 7 more
#VU117390 - Resource exhaustion
CVE-2025-48038
CWE-400 Medium
No
No
23.3.4.9-8 20.10.2025 SB2025102052
SB2025102054
SB2025102055
and 6 more
#VU107594 - Missing Authentication for Critical Function
CVE-2025-32433
CWE-306 Critical
Available
Exploited
21.3.3-6 17.04.2025 SB2025041757
SB2025041763
SB2025042002
and 9 more
#VU106951 - Uncontrolled Memory Allocation
CVE-2025-26618
CWE-789 Medium
No
No
23.3.4.9-5 03.04.2025 SB2025040369
SB2025040384
SB2025040385
and 6 more
#VU106381 - Uncontrolled Memory Allocation
CVE-2025-30211
CWE-789 High
No
No
21.3.3-6, 23.3.4.9-6 02.04.2025 SB2025040211
SB20250403109
SB20250403110
and 7 more


Showing elements 1 - 20 out of 22