🔐 CVE Alert

CVE-2026-66296

UNKNOWN 0.0

Reflected XSS in oaskit's default HTML error handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in lib/oaskit/error_handler/default.ex render request-validation failures as an HTML page whenever the request's Accept header contains html, interpolating request-controlled strings into that page without HTML escaping. The unescaped values are object keys taken from a request body or from an object or deepObject query parameter, which appear in the JSON Schema error's instance path when a schema rejects them (for example under additionalProperties: false), and the raw Content-Type header, reflected in unsupported-media-type errors when it fails to parse. Because browsers send Accept: text/html on ordinary top-level navigation, a crafted GET link is sufficient to trigger the error page; no form submission, custom Content-Type, or attacker-controlled script on the victim's side is required. A payload such as filter[</code></h2><script>alert(document.domain)</script>]=x terminates the enclosing markup and the injected script executes in the origin of the application using oaskit, giving it access to that origin's cookies, session, and same-origin responses. Both HTML error rendering and the vulnerable handler are enabled by default: Oaskit.Plugs.ValidateRequest defaults :html_errors to true and :error_handler to Oaskit.ErrorHandler.Default, so applications following the documented usage are affected without any opt-in. This issue affects oaskit: from 0.1.0 before 0.14.1.

CWE CWE-79
Vendor lud
Product oaskit
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for lud oaskit

Be the first to know when new unknown vulnerabilities affecting lud oaskit are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

lud / oaskit
0.1.0 < 0.14.1
lud / oaskit
552de8ca0ff60617bea58bcafa451892d61a161c < b70c6b2eaf0b11bdd0bbb21b8a87dbb3d46918a1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/lud/oaskit/security/advisories/GHSA-h7xw-x8wr-xpcc cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-66296.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-66296 github.com: https://github.com/lud/oaskit/commit/b70c6b2eaf0b11bdd0bbb21b8a87dbb3d46918a1

Credits

Ludovic Dem Ludovic Dem Jonatan Männchen / EEF