Am I affected?
This record states its affected versions in a form that can't be compared automatically.
≥
eb327f8
<
cdf7260
affected
every other version:
unaffected
Description
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation.
This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Weaknesses & attack patterns
Weakness
CWE-400
·
Uncontrolled Resource Consumption
in catalog →
MITRE ↗
CWE-502
·
Deserialization of Untrusted Data
in catalog →
MITRE ↗
Affected — GitHub / hexpm/hex_core Repository ↗
≥
eb327f8
<
cdf7260
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:*
modules · source files · routines
modules
hex_api
source files
src/hex_api.erl
routines
hex_core:request/4
Affected — Hex / hex_core Hex.pm ↗ Repository ↗
≥
0.1.0
<
0.12.1
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:*
modules · source files · routines
modules
hex_api
source files
src/hex_api.erl
routines
hex_core:request/4
Affected — GitHub / hexpm/hex Repository ↗
≥
314546a
<
636739f
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*
modules · source files · routines
modules
mix_hex_api
source files
src/mix_hex_api.erl
routines
mix_hex_api:request/4
Affected — Hex Mix Integration Repository ↗
≥
2.3.0
<
2.3.2
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:*
modules · source files · routines
modules
mix_hex_api
source files
src/mix_hex_api.erl
routines
mix_hex_api:request/4
Affected — GitHub / erlang/rebar3 Repository ↗
≥
209c02e
<
1d4478f
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
modules · source files · routines
modules
r3_hex_api
source files
apps/rebar/src/vendored/r3_hex_api.erl
routines
r3_hex_api:request/4
Affected — rebar3 Repository ↗
≥
3.9.1
<
3.27.0
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:*
modules · source files · routines
modules
r3_hex_api
source files
apps/rebar/src/vendored/r3_hex_api.erl
routines
r3_hex_api:request/4
References
github.com/hexpm/hex_core ·
GHSA-hx9w-f2w9-9g96 ↗
vendor-advisory
osv.dev ·
EEF-CVE-2026-21619 ↗
related
Credits
Michael Lubas / Paraxial.io
Finder
Jonatan Männchen / EEF
Remediation developer
Eric Meadows-Jönsson / Hex.pm
Remediation reviewer
CVSS breakdown
LOW 2.0
open in calculator →
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N