{"package":"plug","ecosystem":"hex","latest_version":"1.20.3","description":"Compose web applications with functions","license":"Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/elixir-plug/plug","repository":"https://github.com/elixir-plug/plug","downloads_weekly":485111,"health":{"score":41,"risk":"high","breakdown":{"maintenance":20,"popularity":14,"security":13,"maturity":15,"community":9},"deprecated":true,"max_score":100},"vulnerabilities":{"count":4,"critical":0,"high":2,"medium":1,"low":1,"details":[{"vuln_id":"CVE-2026-54892","severity":"high","summary":"Plug: quadratic-time decoding of nested query/body parameters enables denial of service","affected_versions":">=1.15.0,<1.15.5|>=1.16.0,<1.16.4|>=1.17.0,<1.17.2|>=1.18.0,<1.18.3|>=1.19.0,<1.19.3|>=712b875d3442c765d8d37e546ffd5ad9f8afcc55,<a61124aa625d819a218fb07f90afbac8aa85eb0e|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.15.4|=1.16.0|=1.16.1|=1.16.2|=1.16.3|=1.17.0|=1.17.1|=1.18.0|=1.18.1|=1.18.2|=1.19.0|=1.19.1|=1.19.2","fixed_version":"a61124aa625d819a218fb07f90afbac8aa85eb0e","source":"osv","published_at":"2026-06-23T12:31:12.629Z","in_kev":false,"epss_prob":0.00949,"epss_percentile":0.59265,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-56813","severity":"low","summary":"Cookie attribute injection in Plug.Conn.Cookies.encode/2","affected_versions":">=0.1.0,<1.16.6|>=1.17.0,<1.17.4|>=1.18.0,<1.18.5|>=1.19.0,<1.19.5|>=1.20.0,<1.20.3|>=f26876aa67aaeb38e616638aa3efbcc2fe2906a5,<eceb8315ce9a31ef784943a95a8624ebd1bc7e06|=0.10.0|=0.11.0|=0.11.1|=0.11.2|=0.11.3|=0.12.0|=0.12.1|=0.12.2|=0.13.0|=0.13.1|=0.14.0|=0.4.1|=0.4.2|=0.4.3|=0.4.4|=0.5.0|=0.5.1|=0.5.2|=0.5.3|=0.6.0|=0.7.0|=0.8.0|=0.8.1|=0.8.2|=0.8.3|=0.8.4|=0.9.0|=1.0.0|=1.0.1|=1.0.2|=1.0.3|=1.0.4|=1.0.5|=1.0.6|=1.1.0|=1.1.1|=1.1.2|=1.1.3|=1.1.4|=1.1.5|=1.1.6|=1.1.7|=1.1.8|=1.1.9|=1.10.0|=1.10.1|=1.10.2|=1.10.3|=1.10.4|=1.11.0|=1.11.1|=1.12.0|=1.12.1|=1.13.0|=1.13.1|=1.13.2|=1.13.3|=1.13.4|=1.13.5|=1.13.6|=1.14.0|=1.14.1|=1.14.2|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.15.4|=1.15.5|=1.15.6|=1.16.0|=1.16.1|=1.16.2|=1.16.3|=1.16.4|=1.16.5|=1.17.0|=1.17.1|=1.17.2|=1.17.3|=1.18.0|=1.18.1|=1.18.2|=1.18.3|=1.18.4|=1.19.0|=1.19.1|=1.19.2|=1.19.3|=1.19.4|=1.2.0|=1.2.0-rc.0|=1.2.1|=1.2.2|=1.2.3|=1.2.4|=1.2.5|=1.2.6|=1.20.0|=1.20.1|=1.20.2|=1.3.0|=1.3.1|=1.3.2|=1.3.3|=1.3.4|=1.3.5|=1.3.6|=1.4.0|=1.4.0-rc.0|=1.4.1|=1.4.2|=1.4.3|=1.4.4|=1.4.5|=1.5.0|=1.5.0-rc.0|=1.5.0-rc.1|=1.5.0-rc.2|=1.5.1|=1.6.0|=1.6.1|=1.6.2|=1.6.3|=1.6.4|=1.7.0|=1.7.1|=1.7.2|=1.8.0|=1.8.1|=1.8.2|=1.8.3|=1.9.0","fixed_version":"eceb8315ce9a31ef784943a95a8624ebd1bc7e06","source":"osv","published_at":"2026-07-10T12:51:08.758Z","in_kev":false,"epss_prob":0.00203,"epss_percentile":0.10398,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-56814","severity":"medium","summary":"Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)","affected_versions":">=1.4.0,<1.16.6|>=1.17.0,<1.17.4|>=1.18.0,<1.18.5|>=1.19.0,<1.19.5|>=1.20.0,<1.20.3|>=c52b2f32c90bccd718202bafccb5f95594e30183,<df97d3f17f808a9916a7700a701fb85314559d56|=1.10.0|=1.10.1|=1.10.2|=1.10.3|=1.10.4|=1.11.0|=1.11.1|=1.12.0|=1.12.1|=1.13.0|=1.13.1|=1.13.2|=1.13.3|=1.13.4|=1.13.5|=1.13.6|=1.14.0|=1.14.1|=1.14.2|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.15.4|=1.15.5|=1.15.6|=1.16.0|=1.16.1|=1.16.2|=1.16.3|=1.16.4|=1.16.5|=1.17.0|=1.17.1|=1.17.2|=1.17.3|=1.18.0|=1.18.1|=1.18.2|=1.18.3|=1.18.4|=1.19.0|=1.19.1|=1.19.2|=1.19.3|=1.19.4|=1.20.0|=1.20.1|=1.20.2|=1.4.0|=1.4.1|=1.4.2|=1.4.3|=1.4.4|=1.4.5|=1.5.0|=1.5.0-rc.0|=1.5.0-rc.1|=1.5.0-rc.2|=1.5.1|=1.6.0|=1.6.1|=1.6.2|=1.6.3|=1.6.4|=1.7.0|=1.7.1|=1.7.2|=1.8.0|=1.8.1|=1.8.2|=1.8.3|=1.9.0|=v1.20.1|=v1.20.0|=v1.15.3|=v1.17.0|=v1.18.1|=v1.19.1|=v1.18.0|=v1.16.1|=v1.16.0|=v1.15.2|=v1.15.1|=v1.15.0|=v1.14.2|=v1.14.1|=v1.14.0|=v1.13.5|=v1.13.4|=v1.13.3|=v1.13.2|=v1.13.1|=v1.13.0|=v1.12.1|=v1.12.0|=v1.11.1|=v1.11.0|=v1.10.3|=v1.10.2|=v1.10.1|=v1.10.0|=v1.9.0|=v1.8.2|=v1.8.1|=v1.8.0|=v1.7.2|=v1.7.1|=v1.7.0|=v1.6.1|=v1.6.0|=v1.5.1|=v1.5.0|=v1.5.0-rc.2|=v1.5.0-rc.1|=v1.4.3|=v1.5.0-rc.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.4.0-rc.0","fixed_version":"df97d3f17f808a9916a7700a701fb85314559d56","source":"osv","published_at":"2026-07-10T11:14:35.574Z","in_kev":false,"epss_prob":0.01051,"epss_percentile":0.62392,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-8468","severity":"high","summary":"Unbounded buffer accumulation in multipart header parsing causes denial of service in plug","affected_versions":">=1.4.0,<1.15.4|>=1.16.0,<1.16.3|>=1.17.0,<1.17.1|>=1.18.0,<1.18.2|>=1.19.0,<1.19.2|>=c52b2f32c90bccd718202bafccb5f95594e30183,<33858427c7f2737d560a2e40a0c9a9270d77d1d7|=1.10.0|=1.10.1|=1.10.2|=1.10.3|=1.10.4|=1.11.0|=1.11.1|=1.12.0|=1.12.1|=1.13.0|=1.13.1|=1.13.2|=1.13.3|=1.13.4|=1.13.5|=1.13.6|=1.14.0|=1.14.1|=1.14.2|=1.15.0|=1.15.1|=1.15.2|=1.15.3|=1.16.0|=1.16.1|=1.16.2|=1.17.0|=1.18.0|=1.18.1|=1.19.0|=1.19.1|=1.4.0|=1.4.1|=1.4.2|=1.4.3|=1.4.4|=1.4.5|=1.5.0|=1.5.0-rc.0|=1.5.0-rc.1|=1.5.0-rc.2|=1.5.1|=1.6.0|=1.6.1|=1.6.2|=1.6.3|=1.6.4|=1.7.0|=1.7.1|=1.7.2|=1.8.0|=1.8.1|=1.8.2|=1.8.3|=1.9.0|=v1.15.3|=v1.16.2|=v1.17.0|=v1.18.1|=v1.19.1|=v1.18.0|=v1.16.1|=v1.16.0|=v1.15.2|=v1.15.1|=v1.15.0|=v1.14.2|=v1.14.1|=v1.14.0|=v1.13.5|=v1.13.4|=v1.13.3|=v1.13.2|=v1.13.1|=v1.13.0|=v1.12.1|=v1.12.0|=v1.11.1|=v1.11.0|=v1.10.3|=v1.10.2|=v1.10.1|=v1.10.0|=v1.9.0|=v1.8.2|=v1.8.1|=v1.8.0|=v1.7.2|=v1.7.1|=v1.7.0|=v1.6.1|=v1.6.0|=v1.5.1|=v1.5.0|=v1.5.0-rc.2|=v1.5.0-rc.1|=v1.4.3|=v1.5.0-rc.0|=v1.4.2|=v1.4.1|=v1.4.0|=v1.4.0-rc.0","fixed_version":"33858427c7f2737d560a2e40a0c9a9270d77d1d7","source":"osv","published_at":"2026-05-14T10:29:51.062Z","in_kev":false,"epss_prob":0.0062,"epss_percentile":0.47838,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"1.20.3","total_count":138,"recent":["1.20.3","1.20.2","1.20.1","1.20.0","1.19.5","1.19.4","1.19.3","1.19.2","1.19.1","1.19.0","1.18.5","1.18.4","1.18.3","1.18.2","1.18.1","1.18.0","1.17.4","1.17.3","1.17.2","1.17.1"]},"metadata":{"deprecated":true,"deprecated_message":null,"maintainers_count":4,"first_published":"2014-04-23T18:58:52.000000Z","last_published":"2026-07-09T09:42:46.341861Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":3007,"forks":608,"open_issues":4,"is_archived":false,"pushed_at":"2026-07-23T18:05:04+00:00"},"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"find_alternative","issues":["Moderate health score (41/100) — verify manually","2 high severity vulnerabilities","Package is deprecated"],"use_version":"1.20.3","version_hint":"Update to >= 33858427c7f2737d560a2e40a0c9a9270d77d1d7 to fix known vulnerabilities","summary":"plug is deprecated — find an alternative"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/hex/plug","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/hex/plug","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/hex/plug","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate","hint_bulk":"You've called /api/check 269 times in 60s. Save bandwidth + tokens with POST /api/check_bulk (1 round-trip for N pkgs)."},"requested_version":null,"_cache":"hit","_response_ms":3,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":true,"bus_factor_3m":5,"active_contributors_12m":21,"primary_author_ratio":0.4897959183673469,"owner_account_age_days":3207,"is_archived":false,"stars":3000,"alerts":[]},"malicious":{"is_malicious":false},"scorecard":{"available":true,"score":3.8,"tier":"weak"},"quality":{"available":false},"co_used_with":[{"package":"certifi","occurrences":8}],"version_history_summary":{"total_versions":20,"first_release_age_days":4528,"last_release_days_ago":68,"avg_days_between_releases":238,"release_velocity":"active"}}