Compose web applications with functions
plug is deprecated — find an alternative
Update to >= 33858427c7f2737d560a2e40a0c9a9270d77d1d7 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2026-54892 | Plug: quadratic-time decoding of nested query/body parameters enables denial of service | a61124aa625d819a218fb07f90afbac8aa85eb0e |
| low | CVE-2026-56813 | Cookie attribute injection in Plug.Conn.Cookies.encode/2 | eceb8315ce9a31ef784943a95a8624ebd1bc7e06 |
| medium | CVE-2026-56814 | Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service) | df97d3f17f808a9916a7700a701fb85314559d56 |
| high | CVE-2026-8468 | Unbounded buffer accumulation in multipart header parsing causes denial of service in plug | 33858427c7f2737d560a2e40a0c9a9270d77d1d7 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/hex/plugFirst published · 2014-04-23T18:58:52.000000Z
Last updated · 2026-07-09T09:42:46.341861Z