PatchDay Alert

CVE

CVE-2026-40472

0field notes · 1digest CVSS 9.9


Daily digests

Hackage-server (the package repository for Haskell) renders user-supplied metadata from .cabal files straight into HTML links without sanitizing it. A malicious package maintainer can inject stored XSS that fires whenever someone views the package page, potentially stealing session cookies or performing actions as the victim. CVSS 9.9, not yet exploited in the wild.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.