CVE-2026-40472
Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cross-Site Scripting (XSS) attacks.
Published 2026-04-23. Last modified 2026-06-17.