Build log
host
fulib_absinthe 0.1.10 · fail · run fulib_absinthe-0.1.10-1791186217492
260 of 260 lines
1Resolving Hex dependencies...2Resolution completed in 0.634s3Unchanged:4 absinthe 1.12.05 absinthe_plug 1.5.106 certifi 2.15.07 circular_buffer 1.1.08 combine 0.10.09 cowboy 2.6.3 VULNERABLE!10 EEF-CVE-2026-8466 (HIGH)11 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x812 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy13 https://osv.dev/vulnerability/EEF-CVE-2026-84661415 EEF-CVE-2026-65624 (MEDIUM)16 aka: CVE-2026-6562417 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion18 https://osv.dev/vulnerability/EEF-CVE-2026-656241920 GHSA-w4f7-4cxr-rv3c (MEDIUM)21 aka: CVE-2026-43966, EEF-CVE-2026-4396622 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability23 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c24 cowlib 2.7.3 VULNERABLE!25 EEF-CVE-2026-59248 (HIGH)26 aka: CVE-2026-5924827 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-592482930 EEF-CVE-2026-43970 (HIGH)31 aka: CVE-2026-43970, GHSA-84f2-rp86-235p32 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame33 https://osv.dev/vulnerability/EEF-CVE-2026-439703435 EEF-CVE-2026-43968 (MEDIUM)36 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r37 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/138 https://osv.dev/vulnerability/EEF-CVE-2026-439683940 EEF-CVE-2026-7790 (HIGH)41 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6542 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS43 https://osv.dev/vulnerability/EEF-CVE-2026-779044 crc 0.11.045 dataloader 1.0.1146 db_connection 2.10.247 decimal 2.4.1 VULNERABLE!48 EEF-CVE-2026-32686 (MEDIUM)49 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v50 Unbounded exponent in decimal enables unauthenticated DoS51 https://osv.dev/vulnerability/EEF-CVE-2026-3268652 decorator 1.4.053 earmark 1.4.49 RETIRED! VULNERABLE!54 (deprecated) Earmark is no longer maintained. Migrate to a replacement, for example MDEx (https://hex.pm/packages/mdex).5556 EEF-CVE-2026-48591 (MEDIUM)57 aka: CVE-2026-48591, GHSA-52mm-h59v-f3c758 Stored XSS via unescaped HTML attribute values in earmark59 https://osv.dev/vulnerability/EEF-CVE-2026-4859160 ecto 3.13.661 ecto_sql 3.13.562 elixir_make 0.10.063 ex_marshal 0.0.1364 expo 1.1.165 floki 0.38.466 fulib 0.1.1867 fulib_absinthe 0.1.1068 gen_stage 0.14.369 gettext 0.26.270 grpc 0.3.1 VULNERABLE!71 EEF-CVE-2026-48854 (HIGH)72 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj73 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc74 https://osv.dev/vulnerability/EEF-CVE-2026-4885475 gun 1.3.3 VULNERABLE!76 EEF-CVE-2026-43973 (HIGH)77 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7778 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion79 https://osv.dev/vulnerability/EEF-CVE-2026-439738081 GHSA-w4f7-4cxr-rv3c (MEDIUM)82 aka: CVE-2026-43966, EEF-CVE-2026-4396683 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability84 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c85 hackney 1.25.0 VULNERABLE!86 EEF-CVE-2026-47071 (HIGH)87 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr88 SOCKS5 TLS upgrade ignores caller timeout in hackney89 https://osv.dev/vulnerability/EEF-CVE-2026-470719091 EEF-CVE-2026-47076 (MEDIUM)92 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq93 SSRF allowlist bypass via percent-encoded host in hackney94 https://osv.dev/vulnerability/EEF-CVE-2026-470769596 EEF-CVE-2026-47069 (LOW)97 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw298 CRLF injection in cookie domain/path options in hackney99 https://osv.dev/vulnerability/EEF-CVE-2026-47069100101 EEF-CVE-2026-47075 (MEDIUM)102 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf103 CR/LF injection in query parameter in hackney104 https://osv.dev/vulnerability/EEF-CVE-2026-47075105 httpoison 1.8.2106 idna 6.1.1107 inet_cidr 1.0.9108 interactive_cmd 0.1.4109 jason 1.4.5110 jchash 0.1.4111 liquid 0.9.1112 logger_file_backend 0.1.1113 mbcs 1.1.1114 metrics 1.0.1115 mime 2.0.7116 mimerl 1.5.0117 nebulex 1.2.2118 nebulex_cluster 0.1.0119 nebulex_redis_adapter 1.1.1120 nerves 2.0.0-pre.2121 nerves_discovery 0.1.5122 nerves_logging 0.2.4123 nerves_runtime 0.13.13124 nerves_system_bbb 2.30.2125 nerves_system_br 1.34.4126 nerves_system_mangopi_mq_pro 0.17.2127 nerves_system_qemu_aarch64 0.4.2128 nerves_system_rpi0 2.1.2129 nerves_system_rpi4 2.1.2130 nerves_system_rpi5 2.1.2131 nerves_system_trellis 0.5.0132 nerves_system_x86_64 1.34.2133 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1134 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1135 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1136 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1137 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1138 nerves_uevent 0.1.7139 nimble_parsec 1.4.2140 parse_trans 3.4.1141 phoenix_html 2.14.3 VULNERABLE!142 GHSA-5g2h-9x5v-5h3x (MEDIUM)143 aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2144 phoenix_html allows Cross-site Scripting in HEEx class attributes145 https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x146 plug 1.20.3147 plug_cowboy 2.1.3 VULNERABLE!148 EEF-CVE-2026-32688 (HIGH)149 aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg2150 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy151 https://osv.dev/vulnerability/EEF-CVE-2026-32688152 plug_crypto 2.2.0153 postgrex 0.22.4154 property_table 0.3.4155 protobuf 0.17.0156 ranch 1.7.1157 recase 0.9.1158 redix 0.11.2159 remote_ip 0.2.1160 ring_logger 0.11.7161 shards 0.6.2162 shorter_maps 2.2.5163 ssl_verify_fun 1.1.7164 tablet 0.3.3165 telemetry 0.4.3166 timex 3.7.13167 tiny_util 0.2.0168 toolshed 0.5.0169 tzdata 1.2.2170 uboot_env 1.0.2171 unicode_util_compat 0.7.1172 yamerl 0.10.0173Found retired packages, see above for details174Found packages with security advisories, see above for details175All dependencies have been fetched176===> Analyzing applications...177===> Compiling ranch178 ┌─ src/ranch_ssl.erl:179 │180 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of181 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead182183184 ┌─ src/ranch_conns_sup.erl:185 │186 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},187 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.188Compile directive 'nowarn_deprecated_catch' can be used to suppress189warnings in selected modules.190191192make: Entering directory '/work/proj/deps/jchash/c_src'193cc -O3 -std=c99 -finline-functions -Wall -Wmissing-prototypes -fPIC -I /usr/local/lib/erlang/erts-17.1/include/ -I /usr/local/lib/erlang/lib/erl_interface-5.8.2/include -c -o /work/proj/deps/jchash/c_src/jchash.o /work/proj/deps/jchash/c_src/jchash.c194cc /work/proj/deps/jchash/c_src/jchash.o -shared -L /usr/local/lib/erlang/lib/erl_interface-5.8.2/lib -lei -o /work/proj/deps/jchash/c_src/../priv/jchash.so195make: Leaving directory '/work/proj/deps/jchash/c_src'196===> Analyzing applications...197===> Compiling jchash198===> Fetching rebar3_hex v7.3.0199===> Fetching hex_core v0.19.0200===> Fetching verl v1.1.1201===> Analyzing applications...202===> Compiling verl203===> Compiling hex_core204===> Compiling rebar3_hex205===> Analyzing applications...206===> Compiling mbcs207===> Analyzing applications...208===> Compiling shards209 ┌─ src/shards_owner_sup.erl:210 │211 161 │ ok = pg2:create(Tab),212 │ ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead213214 ┌─ src/shards_owner_sup.erl:215 │216 162 │ ok = pg2:join(Tab, self());217 │ ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead218219220 ┌─ src/shards_dist.erl:221 │222 125 │ pg2:join(Tab, shards_lib:get_pid(Tab)).223 │ ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead224225 ┌─ src/shards_dist.erl:226 │227 130 │ Members = [{node(Pid), Pid} || Pid <- pg2:get_members(Tab)],228 │ ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead229230 ┌─ src/shards_dist.erl:231 │232 135 │ {Node, Pid} -> pg2:leave(Tab, Pid);233 │ ╰── Warning: pg2:leave/2 is removed; this module was removed in OTP 24. Use 'pg' instead234235 ┌─ src/shards_dist.erl:236 │237 145 │ lists:usort([node(Pid) || Pid <- pg2:get_members(Tab)]).238 │ ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead239240 ┌─ src/shards_dist.erl:241 │242 440 │ ok = pg2:delete(Tab),243 │ ╰── Warning: pg2:delete/1 is removed; this module was removed in OTP 24. Use 'pg' instead244245 ┌─ src/shards_dist.erl:246 │247 441 │ ok = pg2:create(Name),248 │ ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead249250251===> Analyzing applications...252===> Compiling cowlib253===> Compiling src/cow_sse.erl failed254 ┌─ src/cow_sse.erl:255 │256 56 │ -> {event, parsed_event(), State} | {more, State}.257 │ ╰── type variable 'State' is only used once (is unbound)258259260** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"