CVE-2026-40471 - CERT CVE
ID CVE-2026-40471
Sažetak hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).
Reference
CVSS
Base: 9.6
Impact: 6.0
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Zadnje važnije ažuriranje 24-04-2026 - 14:41
Objavljeno 23-04-2026 - 16:16