xml_builder
Elixir library for generating XML
Activity
- Latest release
- 3w ago
- Total releases
- 21
- Cadence
- ~7 months
- Last 12 months
- 1
Reach
- Downloads
- 74.7M
- Stars
- 187
Details
- License
- MIT
- First release
- Jul 16, 2014
| Version | Released | |
|---|---|---|
2.4.1
patch
| ||
2.4.0
minor
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.3.0
minor
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.2.0
minor
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.4
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.2
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.1.0
minor
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
2.0.0
major
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.1.0
minor
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.9
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.8
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.7
patch
3 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-47080
EEF-CVE-2026-47080
GHSA-67r9-hmxw-h595
Aug 21, 2026
CDATA Section Breakout via Unsanitised ]]> in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files The This issue affects xml_builder: from 0.0.7 before 2.4.1. Affected versions
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
+ 2 more Show less
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.6
patch
2 CVEs
CVE-2026-47079
EEF-CVE-2026-47079
GHSA-5hjx-8g53-cmvm
Aug 21, 2026
Round-trip Corruption via Improper Entity Escaping in xml_builder
Low
Local
Low
None
None
SummaryInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files
This issue affects xml_builder: from 0.0.6 before 2.4.1. Affected versions
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
+ 3 more Show less
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.5
patch
1 CVE
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.4
patch
1 CVE
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.3
patch
1 CVE
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.2
patch
1 CVE
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2026-48590
EEF-CVE-2026-48590
GHSA-r82p-3q2p-728w
Aug 21, 2026
Element and Attribute Names Injected Verbatim into XML Output in xml_builder
Low
Local
Low
None
None
SummaryXML Injection vulnerability in joshnuss xml_builder ( This vulnerability is associated with program files Element names, attribute names, and doctype identifiers are interpolated verbatim into the serialized XML output without validation or escaping of structural characters ( This issue affects xml_builder: from 0.0.1 before 2.4.1. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
+ 8 more Show less
2.0.0
2.1.0
2.1.1
2.1.2
2.1.4
2.2.0
2.3.0
2.4.0
Fixed in
2.4.1
References Updated Sep 08, 2026 · Source: OSV.dev |