SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAwaiting Analysis

CVE-2026-40470

A critical XSS vulnerability affected hackage-server and hackage.haskell.org.

CRITICAL 9.9EPSS 0.31%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses to the package pages or documentation uploaded by a malicious package maintainer, their session can be hijacked to upload packages or documentation, amend maintainers or other package metadata, or perform any other action the user is authorised to do.

CVSS 3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS
0.31% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-79
Source
74b3a70d-cca6-4d34-9789-e83b222ae3be

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.