CVE-2026-40471

CRITICAL

Hackage CSRF vulnerability

Title source: cna
STIX 2.1

Description

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).

References (1)

Core 1

Scores

CVSS v3 9.6
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-352
Status published
Published Apr 23, 2026
Tracked Since Apr 23, 2026