B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-54892 - Plug: quadratic-time decoding of nested query/body parameters enables denial of service

CVE ID :CVE-2026-54892 Published : June 23, 2026, 12:31 p.m. | 39 minutes ago Description :Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Conn.Query.decode/4 (and Plug.Conn.Query.decode_each/2)...

Original-Artikel öffnen Zurück zur Übersicht