CVE-2026-40471

CRITICAL

Hackage CSRF vulnerability

Title source: cna

Description

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).

Scores

CVSS v3 9.6
EPSS 0.0002
EPSS Percentile 4.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Details

CWE
CWE-352
Status published
Published Apr 23, 2026
Tracked Since Apr 23, 2026