Get real-time updates on Telegram
CVE-2026-94206: cloak_ecto 1.0.0-alpha.0 to before *; +1 more affected products
Affected technology
cloak_ecto · 1.0.0-alpha.0 to before *
danielberkompas
cloak_ecto · a8fa1642b02f1c445a1ee8794c9095eb0921f8f3 to before *
danielberkompas
cloak · 0.7.0 to before 1.0.0-alpha.0
danielberkompas
cloak · 8699e6417a162c39d9f0ef63511bd23d3f38d1d2 to before 681c9702b7cd9afe0e5a840751ab009f550c69a9
danielberkompas
Component: 'Elixir.Cloak.Ecto.PBKDF2', 'Elixir.Cloak.Fields.PBKDF2'
File: lib/cloak_ecto/types/pbkdf2.ex, lib/cloak/fields/pbkdf2.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 4.0 assessment (base score 6.3/10) rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-916
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-06 10:41:36.128766+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-06 17:55:17.257073+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-94206.html