CVE-2026-21619

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:*
cpe:2.3:a:hex:hex_core:*:*:*:*:*:*:*:*

History

06 Apr 2026, 17:17

Type Values Removed Values Added
References
  • () https://cna.erlef.org/cves/CVE-2026-21619.html -
  • () https://osv.dev/vulnerability/EEF-CVE-2026-21619 -

23 Mar 2026, 16:49

Type Values Removed Values Added
Summary
  • (es) Consumo de Recursos No Controlado, vulnerabilidad de Deserialización de Datos No Confiables en hexpm hex_core (módulos hex_api), hexpm hex (módulos mix_hex_api), erlang rebar3 (módulos r3_hex_api) permite Inyección de Objetos, Asignación Excesiva. Esta vulnerabilidad está asociada con los archivos de programa src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl y las rutinas de programa hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. Este problema afecta a hex_core: desde 0.1.0 antes de 0.12.1; hex: desde 2.3.0 antes de 2.3.2; rebar3: desde 3.9.1 antes de 3.27.0.
References () https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d - () https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d - Patch
References () https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95 - () https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95 - Patch
References () https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13 - () https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13 - Patch
References () https://github.com/hexpm/hex_core/security/advisories/GHSA-hx9w-f2w9-9g96 - () https://github.com/hexpm/hex_core/security/advisories/GHSA-hx9w-f2w9-9g96 - Mitigation, Vendor Advisory
First Time Hex hex Core
Erlang rebar3
Erlang
Hex hex
Hex
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:hex:hex_core:*:*:*:*:*:*:*:*
cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:*

27 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 18:16

Updated : 2026-04-06 17:17


NVD link : CVE-2026-21619

Mitre link : CVE-2026-21619

CVE.ORG link : CVE-2026-21619


JSON object : View

Products Affected

hex

  • hex
  • hex_core

erlang

  • rebar3
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-502

Deserialization of Untrusted Data