Skip to content

Cabal & Hackage Security History

This log tracks security incidents affecting the cabal-install tool and the Hackage package repository.

PeriodStatusDetails
Week 1 (Dec 1 – 7) SafeNone.
Week 2 (Dec 8 – 14) SafeNone.
Week 3 (Dec 15 – 21) SafeNone.
Week 4 (Dec 22 – 28) SafeNone.
PeriodStatusDetails
Week 1 (Dec 29 – Jan 4) SafeNone.
Week 2 (Jan 5 – Jan 11) SafeNone.
Week 3 (Jan 12 – Jan 18) CriticalJan 16: Infrastructure Breach (HSEC-2024-0004)

Critical Infrastructure Breach (HSEC-2024-0004)

Section titled “Critical Infrastructure Breach (HSEC-2024-0004)”
  • Target: hackage-server and hackage.haskell.org
  • Vulnerability: Stored Cross-Site Scripting (XSS)
  • Impact:
    • Malicious HTML/JS files could be served via source packages or documentation uploads.
    • This exposed users to potential session hijacking when viewing compromised package pages.
  • Resolution:
    • The Haskell Security Response Team (SRT) publicly disclosed the issue.
    • Mitigation: User content was migrated to a sandboxed domain (hackage-content.haskell.org) to prevent script execution on the main domain.