CVE-2026-21619

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
3
PROJECTS

Description

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.erl, src/mix_hex_api.erl, apps/rebar/src/vendored/r3_hex_api.erl and program routines hex_core:request/4, mix_hex_api:request/4, r3_hex_api:request/4. This issue affects hex_core: from 0.1.0 before 0.12.1; hex: from 2.3.0 before 2.3.2; rebar3: from 3.9.1 before 3.27.0.

Package manager for the Erlang ecosystem.
GitHubGitHub
1.07K
Reference implementation of Hex specifications.
GitHubGitHub
105
Erlang build tool that makes it easy to compile and test Erlang applications and releases.
GitHubGitHub
1.81K