Home

Description

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).

PUBLISHED Reserved 2026-04-13 | Published 2026-04-23 | Updated 2026-04-23 | Assigner redhat-cnalr




CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Problem types

CWE-352 Cross-Site request forgery (CSRF)

Product status

Default status
unaffected

0.1 (semver) before *
affected

References

osv.dev/vulnerability/HSEC-2026-0002

cve.org (CVE-2026-40471)

nvd.nist.gov (CVE-2026-40471)

Download JSON