CVE-2026-40472
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sani
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.
CRITICAL · CVSS 9.9
EPSS 0.00059
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0