CVE-2026-40470
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
23/04/2026
Última modificación:
24/04/2026
Descripción
*** Pendiente de traducción *** A critical XSS vulnerability affected hackage-server and<br />
hackage.haskell.org. HTML and JavaScript files provided in source<br />
packages or via the documentation upload facility were served<br />
as-is on the main hackage.haskell.org domain. As a consequence,<br />
when a user with latent HTTP credentials browses to the package<br />
pages or documentation uploaded by a malicious package maintainer,<br />
their session can be hijacked to upload packages or<br />
documentation, amend maintainers or other package metadata, or<br />
perform any other action the user is authorised to do.
Impacto
Puntuación base 3.x
9.90
Gravedad 3.x
CRÍTICA



