216.73.217.22

CVE-2026-40471

· Published 23/04/2026 16:16 · Modified 24/04/2026 14:41

Labels: CVE-2026-40471 2026-04-2374b3a70d-cca6-4d34-9789-e83b222ae3beCVE-2026-40471CWE-352

Essential information

Published
23/04/2026 16:16
Modified
24/04/2026 14:41
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

CVSS metrics

Description

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
74b3a70d-cca6-4d34-9789-e83b222ae3be
NVD
View on NVD

Affected products (CPE)

ProductCPE
hackage / hackage-server cpe:2.3:a:hackage:hackage-server:*:*:*:*:*:*:*:*

References