Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 27 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0. | |
| Title | Unsafe Deserialization of Erlang Terms in hex_core | |
| First Time appeared |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| Weaknesses | CWE-400 CWE-502 |
|
| CPEs | cpe:2.3:a:erlang:rebar3:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex:*:*:*:*:*:*:*:* cpe:2.3:a:hexpm:hex_core:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Erlang
Erlang rebar3 Hexpm Hexpm hex Hexpm hex Core |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-02-27T19:08:57.019Z
Reserved: 2026-01-01T03:46:45.933Z
Link: CVE-2026-21619
No data.
Status : Received
Published: 2026-02-27T18:16:11.373
Modified: 2026-02-27T18:16:11.373
Link: CVE-2026-21619
No data.
OpenCVE Enrichment
No data.