LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40471

CVE-2026-40471 - Vulnerability Analysis

CriticalCVSS: 9.6

Last Updated: April 23, 2026

hackage-server - Cross-Site Request Forgery

Published: April 23, 2026Updated: April 23, 2026Remote Exploitable

Overview

hackage-server contains a cross-site request forgery vulnerability caused by lack of CSRF protection across endpoints, letting attackers trigger unauthorized actions including package uploads and user account creation, exploit requires victim interaction.

Severity & Score

Severity: Critical
CVSS Score: 9.6

Impact

Attackers can perform unauthorized administrative actions or create user accounts by exploiting victim's credentials via CSRF.

Mitigation

Update to the latest version with CSRF protections implemented.

Details

CVE ID
CVE-2026-40471
Severity
Critical
CVSS Score
9.6
Type
cross_site_request_forgery
Status
new

CWE

  • CWE-352

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L