CVE-2017-1000052: Plug Project Plug
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
Affected products
- Plug Project Plug: from 1.0.0, before 1.0.4 (fixed in 1.0.4); from 1.1.0, before 1.1.7 (fixed in 1.1.7); from 1.2.0, before 1.2.3 (fixed in 1.2.3); from 1.3.0, before 1.3.2 (fixed in 1.3.2)
Published 2017-07-17. Last modified 2026-06-17.