Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
References
Configurations
Configuration 1 (hide)
|
History
06 Apr 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Mar 2026, 16:49
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://github.com/erlang/rebar3/commit/1d4478f527e373de0b225951e53115450e0d9b9d - Patch | |
| References | () https://github.com/hexpm/hex/commit/636739f3322514e9303ca335fb630696fcbb3c95 - Patch | |
| References | () https://github.com/hexpm/hex_core/commit/cdf726095bca85ad2549d146df1e831ae93c2b13 - Patch | |
| References | () https://github.com/hexpm/hex_core/security/advisories/GHSA-hx9w-f2w9-9g96 - Mitigation, Vendor Advisory | |
| First Time |
Hex hex Core
Erlang rebar3 Erlang Hex hex Hex |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CPE | cpe:2.3:a:hex:hex_core:*:*:*:*:*:*:*:* cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:* cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:* |
27 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-27 18:16
Updated : 2026-04-06 17:17
NVD link : CVE-2026-21619
Mitre link : CVE-2026-21619
CVE.ORG link : CVE-2026-21619
JSON object : View
Products Affected
hex
- hex
- hex_core
erlang
- rebar3
